For the complete documentation index, see llms.txt. This page is also available as Markdown.

ARTICLE XVII. COMPLIANCE

Section 393. Compliance Purpose and Compliance Domains

393.1 Compliance Purpose. GCRI Canada shall maintain a legal, corporate, nonprofit, tax, privacy, AI governance, cybersecurity, research ethics, employment, contractor, sanctions, export-control, competition, procurement-neutrality, professional-boundary, public authority-boundary, finance-boundary, safeguards, public-safe claims, investigation, enforcement, and compliance-record framework to ensure that GCRI Canada operates as a serious Canadian public-benefit institution. Compliance shall be understood as an institutional architecture for lawful conduct, public trust, mission fidelity, public-good stewardship, legal separateness, non-execution, validity-by-record, correctionability, and Nexus role separation, and not merely as a defensive administrative function. Every compliance domain shall be interpreted to preserve GCRI Canada’s upstream role as a steward of research, evidence, methods, observability, ontology, public-good software, open technical baselines, public-safe publication, technical literacy, public authority learning, and controlled Nexus-compatible interfaces.

393.2 Compliance as Public-Benefit Duty. Compliance is a public-benefit duty of GCRI Canada because lawful, disciplined, accurate, record-supported, non-capturable, and correctionable institutional conduct is necessary to protect the public-good character of GCRI Canada’s work. GCRI Canada shall not pursue speed, scale, donor preference, sponsor visibility, provider access, public authority proximity, publication momentum, media interest, capital-reader interest, program growth, technical ambition, or institutional prestige at the expense of compliance. Compliance shall be applied to prevent legal breach, public authority confusion, data misuse, AI misuse, cyber exposure, research distortion, protected knowledge harm, finance-boundary drift, procurement steering, certification implication, professional overclaim, public warning implication, emergency command implication, and improper private benefit.

393.3 Compliance as Board Oversight Duty. The Board shall oversee GCRI Canada’s compliance posture and shall ensure that compliance responsibilities, escalation pathways, reporting lines, records, reviews, policies, controls, and corrective mechanisms are reasonably established and maintained in proportion to GCRI Canada’s size, risk, activities, public authority interfaces, data / AI / cyber exposure, research activities, public-safe publication activities, funding relationships, technical asset stewardship, Academy activities, fellowship activities, public-good software activities, and Nexus-compatible interfaces. Board oversight of compliance shall include attention to corporate status, nonprofit and tax posture, conflicts, restricted funds, public authority boundaries, finance boundaries, provider neutrality, sponsor non-control, privacy, cybersecurity, AI governance, research ethics, workplace obligations, sanctions, export controls, competition law, investigation integrity, and correctionability.

393.4 Compliance as Officer and Management Duty. Officers, managers, program owners, custodians, maintainers, publication approvers, data / AI / cyber leads, safeguards leads, finance personnel, research leads, Academy leads, committee chairs, council stewards, controlled-room custodians, repository custodians, and other authorized persons shall administer compliance within their authority. This duty includes identifying applicable requirements, preventing prohibited conduct, maintaining records, escalating uncertainty, implementing controls, preserving evidence, correcting errors, respecting non-execution boundaries, protecting public authority boundaries, safeguarding sensitive data and protected knowledge, enforcing access controls, and refusing or pausing activities that cannot be performed lawfully or safely. Delegation of compliance tasks shall not eliminate the responsibility to escalate material issues.

393.5 Compliance as Condition of Participation. Participation in GCRI Canada programs, governance, advisory bodies, councils, committees, working parties, fellowships, Academy programs, competence cells, research collaborations, public authority learning, controlled rooms, data rooms, labs, challenges, benchmarking, software repositories, technical contribution pathways, public-safe publication processes, sponsorships, grants, donations, subscriptions, host activations, and Nexus-compatible interfaces shall be conditioned on compliance with applicable law, this Bylaw, approved policies, program rules, confidentiality obligations, data / AI / cyber requirements, public authority boundaries, safeguards, conflict rules, publication controls, non-retaliation, and public-safe claims discipline. GCRI Canada may restrict, suspend, revoke, terminate, correct, or condition participation where compliance risk is material.

393.6 Corporate Compliance. Corporate compliance shall include maintenance of GCRI Canada’s legal existence, Articles and constituting instrument compliance, Bylaw compliance, registered office compliance, corporate filings, annual returns, director and officer records, member records where applicable, minute books, resolutions, statutory registers, corporate changes, corporate calendar, corporate authority, signing authority, legal separateness, and corporate record integrity. Corporate compliance shall preserve GCRI Canada as a distinct Canadian legal institution and shall prevent informal merger, shared treasury, shared liability, unauthorized authority, role confusion, or Nexus entity collapse.

393.7 Nonprofit Compliance. Nonprofit compliance shall include compliance with GCRI Canada’s nonprofit, non-share, non-distributing, public-benefit, mission-locked, non-executing posture. Nonprofit compliance shall require public-benefit use of funds, no improper private inurement, no unlawful distribution, no control-for-cash, no pay-to-play, no private capture of public-good assets, and no use of nonprofit status to create hidden provider preference, sponsor benefit, finance-readiness advantage, public authority access purchase, certification purchase, recognition purchase, or procurement advantage.

393.8 Tax Compliance. Tax compliance shall include compliance with filing obligations, remittance obligations, GST/HST or sales tax obligations where applicable, payroll tax obligations where applicable, withholding obligations where applicable, non-charitable payment treatment unless status lawfully changes, donation receipt controls where applicable, grant and restricted-fund tax treatment, sponsorship and commercial revenue treatment, membership and subscription treatment, training and Academy fee treatment, fellowship and stipend treatment, cross-border tax considerations, related-party review, and tax-risk escalation. Tax compliance shall support truthful public language and prevent misleading charitable, donation, sponsorship, subscription, or public-benefit claims.

393.9 Privacy Compliance. Privacy compliance shall include compliance with applicable Canadian, provincial, territorial, public-sector, health information, research, public authority data, cross-border, consent, notice, lawful basis, purpose limitation, minimization, access, correction, deletion, complaint, breach notification, processor, and service provider requirements. Privacy compliance shall apply to personal information, rights-bearing data, community data, public authority data, research data, health-sensitive data, protected participation records, whistleblowing records, employment records, controlled-room records, Academy records, and AI-assisted processing.

393.10 AI Governance Compliance. AI governance compliance shall include AI system inventory, model register discipline, AI-use authorization, risk classification, human review, model evaluation, agentic AI controls, prompt and retrieval controls, embedding and model-training restrictions, AI vendor review, hallucination and fabricated citation controls, AI incident reporting, AI transparency and disclosure where required, public-safe publication review, bias review, drift review, public authority boundary review, protected knowledge review, and correction. AI governance compliance shall ensure that AI supports evidence, methods, research, literacy, and public-safe publication without becoming unreviewed authority, public warning, emergency command, finance advice, certification, procurement approval, or public authority decision.

393.11 Cybersecurity Compliance. Cybersecurity compliance shall include security governance, minimum cybersecurity baseline, identity and access management, MFA, least privilege, secure configuration, logging, monitoring, vulnerability management, secure development, repository security, release security, incident response, backup, disaster recovery, business continuity, cyber-sensitive data handling, infrastructure-sensitive data handling, public authority data security, vendor security, cloud security, AI provider security, and security training. Cybersecurity compliance shall protect GCRI Canada’s public-good technical assets, records, public authority data, protected knowledge, software repositories, controlled rooms, and institutional continuity.

393.12 Research Ethics Compliance. Research ethics compliance shall include research integrity, human-subjects review where applicable, research ethics board or equivalent review where applicable, community review where appropriate, Indigenous / local / territorial / cultural / environmental and protected knowledge review, health-sensitive research controls, vulnerable participant safeguards, consent, non-consent, withdrawal, correction, sponsor and provider influence controls, research conflict controls, publication integrity, misconduct review, correction, retraction, and research ethics training. Research ethics compliance shall prevent extraction, unsafe publication, sponsor-driven findings, provider-driven conclusions, public authority misuse, AI misuse, and uncorrectable harm.

393.13 Employment, Contractor, Volunteer, Fellow, Advisor, and Workplace Compliance. Employment, contractor, volunteer, fellow, advisor, seconded personnel, and workplace compliance shall include written engagement terms, worker classification, compensation, reimbursement, stipend, scholarship, award, benefit, confidentiality, intellectual property, work product, data access, AI-use, cybersecurity, workplace health and safety, accessibility, harassment, violence, discrimination, anti-retaliation, onboarding, training, supervision, discipline, and offboarding controls. GCRI Canada shall ensure that persons acting for or with it understand their roles, limits, authority, confidentiality duties, access limits, public statement limits, and correction obligations.

393.14 Contract Compliance. Contract compliance shall include compliance with agreements, memoranda, grants, donation agreements, sponsorship agreements, subscription terms, host agreements, research agreements, data-sharing agreements, vendor agreements, contractor agreements, fellowship agreements, licensing agreements, IP agreements, software agreements, cloud agreements, AI provider agreements, public authority agreements, controlled-room terms, and publication terms. Contract compliance shall include authority, scope, payment, records, deliverables, data rights, AI-use restrictions, cyber obligations, confidentiality, publication rights, IP, termination, closeout, and correction.

393.15 Grant, Donation, Sponsorship, and Restricted-Fund Compliance. Grant, donation, sponsorship, underwriting, in-kind, subscription, and restricted-fund compliance shall ensure that support is accepted, used, reported, acknowledged, restricted, corrected, returned, reallocated, or closed out according to law, agreements, restrictions, Board approval, nonprofit purposes, tax treatment, no-private-inurement rules, sponsor non-control, donor non-control, provider neutrality, public authority boundaries, finance-boundary controls, certification-boundary controls, procurement-neutrality controls, research integrity, public-safe publication, and correctionability.

393.16 Public Authority Boundary Compliance. Public authority boundary compliance shall preserve capacity classification, official capacity records, reference controls, data contribution controls, public authority non-endorsement, no delegation, no public-private partnership by participation, no public warning, no emergency command, no regulatory approval, no procurement approval, no funding approval, no public finance approval, no sovereign obligation, no adoption by attendance, and public authority correction. Public authority proximity shall be treated as a compliance risk requiring precision, not as a marketing asset.

393.17 Sanctions and Export-Control Compliance. Sanctions and export-control compliance shall include screening, restricted-party review, controlled technology review, national security sensitivity review, public-sector sensitivity review, cross-border transfer review, publication review, access control, repository control, collaboration control, AI-RAN / O-RAN review, DePIN and DLT review, cyber tool review, cryptography review, geospatial and Earth observation review, satellite and remote-sensing review, drone and robotics review, quantum-adjacent review, dual-use review, and denial, restriction, licensing, or escalation where required. GCRI Canada shall not permit public-good language to obscure controlled technology obligations.

393.18 Competition and Antitrust Compliance. Competition and antitrust compliance shall prevent price coordination, bid coordination, market allocation, provider exclusion, procurement steering, market-sensitive information exchange, sponsor or provider capture of benchmarking, anti-competitive clean-room misuse, improper competitor collaboration, and use of GCRI Canada programs to coordinate commercial conduct. Competition compliance shall apply to benchmarking, market baseline libraries, capability mapping, challenges, labs, provider participation, public authority rooms, sponsor events, and controlled discussions.

393.19 Professional Boundary Compliance. Professional boundary compliance shall ensure that GCRI Canada does not provide regulated professional services, legal advice, investment advice, securities advice, insurance advice, lending advice, underwriting, rating, public finance approval, engineering approval, clinical advice, accounting opinion, procurement advice, certification, accreditation, compliance approval, emergency command, public warning, or public authority decision unless separately lawful, competent, authorized, and controlled. GCRI Canada outputs shall be evidence, methods, research, learning, public-safe publication, or technical baseline artifacts unless expressly authorized otherwise.

393.20 Data, AI, Cyber, Publication, Safeguards, and Public-Safe Claims Compliance. Data, AI, cyber, publication, safeguards, and public-safe claims compliance shall ensure that GCRI Canada’s outputs are source-supported, method-supported, limitation-bearing, public-safe, classification-controlled, access-controlled, cyber-secure, privacy-compliant, AI-reviewed where applicable, safeguards-reviewed where applicable, public authority-reviewed where required, sponsor and provider reference-reviewed where required, finance-boundary-reviewed where required, and correctionable. Public claims shall not overstate evidence, confidence, public authority involvement, finance-readiness, certification, procurement significance, recognition, maturity, public warning, or emergency command.

393.21 Compliance Escalation. Compliance uncertainty, suspected breach, material incident, boundary overclaim, public authority confusion, privacy issue, AI incident, cyber incident, research integrity issue, safeguards issue, public-safe publication issue, finance-boundary issue, procurement-boundary issue, certification implication, sanctions issue, export-control issue, competition issue, workplace issue, protected participation issue, or retaliation issue shall be escalated through the appropriate officer, committee, Board, counsel, safeguards function, data / AI / cyber function, research integrity function, public authority boundary reviewer, finance-boundary reviewer, or other competent pathway. Escalation shall be timely, record-supported, proportionate, and protective of evidence and affected persons.

393.22 Compliance Records. GCRI Canada shall maintain compliance records, including compliance purpose records, public-benefit duty records, Board oversight records, officer and management duty records, participation condition records, corporate compliance records, nonprofit compliance records, tax compliance records, privacy compliance records, AI governance compliance records, cybersecurity compliance records, research ethics compliance records, employment / contractor / volunteer / fellow / advisor / workplace compliance records, contract compliance records, grant / donation / sponsorship / restricted-fund compliance records, public authority boundary compliance records, sanctions and export-control compliance records, competition and antitrust compliance records, professional boundary compliance records, data / AI / cyber / publication / safeguards / public-safe claims compliance records, escalation records, corrective action records, enforcement records, appeal records where applicable, closeouts, and archives.


Section 394. Corporate Compliance

394.1 Corporate Compliance Purpose. GCRI Canada shall maintain corporate compliance to preserve its legal existence, corporate capacity, governance validity, legal separateness, record integrity, Board authority, officer authority, member structure where applicable, nonprofit character, public-benefit mission, non-execution posture, and institutional continuity. Corporate compliance shall support validity-by-record by ensuring that corporate actions, governance decisions, filings, appointments, resignations, amendments, authorizations, delegations, minutes, resolutions, registers, and statutory records are properly recorded and retrievable. Corporate compliance shall also prevent informal authority, role confusion, unauthorized corporate acts, improper use of GCRI Canada name, and collapse of GCRI Canada into any other Nexus institution, public authority, sponsor, provider, host, National Consortium Company, Project SPV, or affiliated body.

394.2 Maintenance of Legal Existence. GCRI Canada shall take reasonable and lawful steps to maintain its legal existence as a Canadian corporation or other lawful Canadian legal form established by its constituting instruments and applicable law. Maintenance of legal existence includes filing required returns, maintaining a registered office, maintaining directors and officers as required, keeping records, paying required fees, responding to corporate notices, maintaining governance records, and avoiding administrative dissolution, default, or loss of status. Any threat to legal existence shall be escalated to the Board and addressed promptly.

394.3 Articles and Constituting Instrument Compliance. GCRI Canada shall comply with its Articles, letters patent, certificate, continuance documents, corporate charter, or other constituting instruments. No Bylaw provision, Board resolution, officer action, program instrument, grant agreement, sponsorship agreement, public authority arrangement, Nexus-compatible interface, public-good software release, technical baseline, or public statement shall be interpreted to override the Articles or constituting instruments except through a lawful amendment. Where ambiguity exists, GCRI Canada shall interpret governance authority consistently with its public-benefit purpose, nonprofit character, non-distribution posture, and non-execution boundaries.

394.4 Bylaw Compliance. GCRI Canada shall comply with this Bylaw as the internal governance instrument governing corporate affairs, Board authority, officer authority, participation, programs, compliance, public authority boundaries, finance boundaries, data / AI / cyber obligations, public-safe publication, safeguards, records, correction, and institutional role separation. Persons acting for or with GCRI Canada shall not rely on informal custom, prior practice, urgency, donor preference, sponsor expectation, provider expectation, public authority pressure, or operational convenience to bypass this Bylaw. Bylaw breaches shall be corrected, ratified where lawful, reversed where required, or escalated.

394.5 Registered Office Compliance. GCRI Canada shall maintain a registered office, records office, or other required corporate address in accordance with applicable law and corporate filings. The registered office shall be used for statutory notices, official correspondence, service where applicable, corporate records location where required, and corporate governance communications. Changes to the registered office shall be authorized, filed, recorded, and communicated as required. The registered office shall not be used to imply operational control, public authority status, regional mandate, public-private partnership, or presence in jurisdictions beyond what is legally accurate.

394.6 Corporate Filings. GCRI Canada shall make corporate filings required by applicable law, including filings concerning incorporation, continuance, directors, officers where required, registered office, annual returns, amendments, bylaw changes where required, changes in corporate status, amalgamation, reorganization, dissolution, or other statutory matters. Corporate filings shall be accurate, timely, authorized, and supported by records. Filings shall not include misleading public-benefit claims, charitable status claims, public authority claims, Nexus role claims, finance-readiness claims, certification claims, or operational authority claims.

394.7 Annual Returns. GCRI Canada shall file annual returns or equivalent corporate maintenance filings where required. Annual returns shall be prepared using current corporate records, director records, officer records where applicable, registered office information, member information where applicable, and other required information. Failure to file an annual return, receipt of default notice, or risk of administrative dissolution shall be escalated and corrected promptly. Annual return filing shall be recorded.

394.8 Director Records. GCRI Canada shall maintain accurate director records, including director names, addresses or service addresses where required, consent to act, appointment records, election records, term records, resignation records, removal records, vacancy records, qualification records, disqualification reviews, conflict disclosures, training records, attendance records, committee roles, Board roles, and statutory filing records. Director records shall support legal authority, fiduciary accountability, public-benefit oversight, conflict management, and validity of Board action.

394.9 Officer Records. GCRI Canada shall maintain officer records identifying officer appointments, titles, authority, delegated powers, signing authority, reporting obligations, resignation, removal, replacement, conflict disclosures, confidentiality obligations, data / AI / cyber access, public statement authority, employment or contract status where applicable, and offboarding. Officer records shall distinguish corporate officer authority from staff role, program role, public authority relationship, sponsor relationship, technical expertise, advisory role, and Nexus interface role. No person shall claim officer authority without a competent record.

394.10 Member Records Where Applicable. Where GCRI Canada has statutory members, voting members, non-voting members, or any other lawful membership class, it shall maintain member records required by law, Articles, and this Bylaw. Member records shall identify admission, class, rights, restrictions, good standing, voting rights where any, notice rights, meeting records, resignation, suspension, termination, reinstatement, and member approvals where required. Participation, subscription, donation, sponsorship, attendance, contribution, authorship, public authority participation, provider participation, or technical access shall not create membership unless a lawful record expressly does so.

394.11 Minute Books. GCRI Canada shall maintain minute books and corporate records required by law and good governance practice. Minute books shall include Articles or constituting instruments, Bylaws, amendments, Board minutes, Board resolutions, member minutes where applicable, member resolutions where applicable, director registers, officer records, statutory registers, annual returns, filings, committee records where required, and other material corporate records. Minute books may be electronic, physical, or hybrid, provided they are secure, accessible to authorized persons, auditable, and retained according to law.

394.12 Board Resolutions. Board resolutions shall be recorded to evidence Board decisions, approvals, delegations, appointments, budgets, policies, major contracts, major compliance actions, amendments, filings, officer appointments, committee charters, signing authority, restricted-fund approvals, public authority-sensitive approvals, and other material corporate actions. Resolutions shall identify date, authority, quorum, approval, abstentions, recusals, conflicts, materials reviewed, and action items where appropriate. Board resolutions shall not be replaced by informal messages, verbal understandings, donor directions, sponsor expectations, or public authority communications.

394.13 Member Resolutions Where Applicable. Where member approval is required by law, Articles, or this Bylaw, member resolutions shall be recorded according to applicable notice, quorum, voting, written resolution, electronic participation, and approval requirements. Member resolutions shall be limited to matters within lawful member authority. Members shall not direct research conclusions, evidence, methods, technical baselines, public-safe publications, public authority access, finance-readiness language, certification language, procurement outcomes, or GCRI Canada’s non-executing public-good functions unless such authority is lawfully provided and consistent with this Bylaw.

394.14 Committee and Council Records Where Required. GCRI Canada shall maintain committee, advisory council, council, working-party, expert-panel, peer-review, model-review, competence-cell, and other internal or advisory body records where required by law, Board policy, charter, program rules, public authority terms, research integrity, data / AI / cyber requirements, public-safe publication rules, or this Bylaw. Such records shall identify mandate, membership, capacity, conflicts, confidentiality, materials reviewed, recommendations, limitations, non-binding status where applicable, corrections, and closeout. Advisory records shall not be treated as Board decisions unless adopted by competent authority.

394.15 Corporate Seal and Certification Where Applicable. Where GCRI Canada uses a corporate seal, certified copies, certificates, attestations, incumbency confirmations, corporate extracts, or officer certificates, such instruments shall be issued only by authorized persons and shall accurately reflect corporate records. Corporate certification shall be limited to corporate status, authority, documents, or records within GCRI Canada’s competence. No corporate seal, certificate, or attestation shall be used to certify providers, public authority approval, finance-readiness, procurement approval, public warning, technical performance, recognition, maturity, or compliance of third parties unless separately lawful and expressly authorized.

394.16 Statutory Registers. GCRI Canada shall maintain statutory registers required by applicable law, which may include registers of directors, officers, members, debt obligations where applicable, interests, securities where applicable, or other statutory records. Statutory registers shall be accurate, updated, access-controlled, and retained. Errors in statutory registers shall be corrected promptly, and material errors shall be escalated where they may affect authority, filings, governance validity, member rights, or corporate compliance.

394.17 Corporate Changes, Amendments, Continuance, Amalgamation, Reorganization, or Dissolution Compliance. Corporate changes, amendments to Articles, bylaw amendments where required, continuance, amalgamation, reorganization, dissolution, winding-up, asset transfer, name change, legal status change, charitable status change, nonprofit status change, member structure change, or material governance restructuring shall be conducted only through lawful procedures and competent authority. Such actions shall be reviewed for public-benefit mission lock, nonprofit and non-distribution character, public-good asset treatment, restricted-fund obligations, donor and grant obligations, public authority terms, data / AI / cyber continuity, protected knowledge, public-safe publication, Nexus role separation, no merger, no shared treasury, and no unintended liability.

394.18 Corporate Compliance Calendar. GCRI Canada shall maintain a corporate compliance calendar or equivalent tracking system for filings, annual returns, director terms, officer appointments, member meetings where applicable, annual financial statements, tax filings, audit or review deadlines, insurance renewals, policy reviews, registered office updates, statutory register reviews, Board evaluation, compliance reviews, restricted-fund reports, public authority terms, and other corporate deadlines. The compliance calendar shall identify responsible persons, deadlines, status, escalations, and completion records. Missed deadlines shall be corrected and reviewed for root cause where material.

394.19 Corporate Compliance Records. GCRI Canada shall maintain corporate compliance records, including corporate compliance purpose records, legal existence records, Articles and constituting instrument records, Bylaw compliance records, registered office records, corporate filings, annual returns, director records, officer records, member records where applicable, minute books, Board resolutions, member resolutions where applicable, committee and council records where required, corporate seal and certification records, statutory registers, corporate change records, amendment records, continuance records, amalgamation records, reorganization records, dissolution records, corporate compliance calendars, default notices, corrections, ratifications where lawful, legal reviews, Board reviews, closeouts, and archives.


Section 395. Tax and Nonprofit Compliance

395.1 Tax and Nonprofit Compliance Purpose. GCRI Canada shall maintain tax and nonprofit compliance to preserve its public-benefit purpose, nonprofit character, non-share and non-distributing posture, non-charitable posture unless lawfully changed, lawful tax treatment, truthful receipting, proper reporting, appropriate revenue classification, restricted-fund accountability, no-private-inurement discipline, and public trust. Tax and nonprofit compliance shall support mission fidelity and shall prevent improper private benefit, misleading charitable claims, disguised commercial activity, unsupported donation treatment, tax misclassification, sponsor influence, provider preference, procurement advantage, finance-readiness influence, certification purchase, recognition purchase, or public authority access purchase.

395.2 Nonprofit Purpose Compliance. GCRI Canada shall conduct its affairs for public-benefit nonprofit purposes consistent with its Articles, this Bylaw, applicable law, Board-approved strategy, and approved programs. Nonprofit purpose compliance requires that resources, activities, publications, programs, grants, donations, sponsorships, subscriptions, fees, public-good assets, public authority interfaces, Academy programs, fellowships, software, technical baselines, and Nexus-compatible activities advance lawful public-benefit objectives rather than private commercial advantage, personal benefit, sponsor control, provider preference, or capital promotion. Activities inconsistent with nonprofit purpose shall be refused, re-scoped, corrected, or terminated.

395.3 Non-Distribution Compliance. GCRI Canada shall not distribute profits, surplus, assets, dividends, equity-like interests, residual claims, private earnings, or nonprofit value to directors, officers, members, participants, subscribers, donors, sponsors, providers, hosts, partners, employees, contractors, fellows, advisors, public authorities, capital actors, National Consortium Companies, Project SPVs, or private persons except through lawful, reasonable, recorded compensation, reimbursement, stipend, scholarship, award, grant, contract payment, refund, or other bona fide public-benefit or operational payment. Non-distribution compliance shall apply during operations, reorganization, dissolution, winding-up, asset transfer, and program closeout.

395.4 No Private Inurement Compliance. GCRI Canada shall review transactions, payments, benefits, access, acknowledgments, sponsorships, subscriptions, fellowships, awards, procurement, grants, in-kind support, public authority access, data access, technical asset access, software access, public-good baselines, and publication opportunities to prevent improper private inurement. Private benefit that is incidental, reasonable, mission-related, and lawfully approved may be permitted, but improper benefit, insider benefit, hidden compensation, related-party advantage, sponsor benefit beyond approved schedule, provider preference, public authority access purchase, finance-readiness purchase, certification purchase, or recognition purchase is prohibited. Material concerns shall be escalated.

395.5 Non-Charitable Status Compliance Unless Lawfully Changed. Unless and until GCRI Canada lawfully obtains charitable status or another legally distinct tax status, GCRI Canada shall communicate, receipt, invoice, acknowledge, and report payments consistently with its non-charitable nonprofit posture. GCRI Canada shall not issue charitable tax receipts, imply registered charity status, imply charitable deductibility, use charitable fundraising language where inaccurate, or allow donors, sponsors, funders, public authorities, providers, media, or participants to misdescribe its status. If charitable status is pursued or obtained, the Board shall approve updated governance, receipting, fundraising, gift acceptance, public language, asset-lock, and compliance controls.

395.6 Charitable Status Controls if Lawfully Obtained. If GCRI Canada lawfully obtains charitable status or any equivalent tax-recognized status, it shall comply with all applicable requirements of that status, including charitable purpose, receipting, disbursement, books and records, public benefit, private benefit limits, fundraising rules, political activity rules where applicable, foreign activity rules where applicable, direction and control or equivalent requirements where applicable, annual filings, gift acceptance, restricted funds, and revocation risk controls. Charitable status shall not authorize public authority delegation, finance-readiness, certification, procurement approval, public warning, emergency command, or provider endorsement.

395.7 Tax Filing Compliance. GCRI Canada shall file required tax returns, information returns, nonprofit returns, corporate returns, sales tax returns, payroll returns, charity returns where applicable, foreign reporting where applicable, and other tax filings required by law. Filings shall be accurate, timely, supported by books and records, reviewed by authorized persons, and escalated where uncertainty or risk is material. Tax filing compliance shall include record retention, professional advice where appropriate, Board review of material filings, and correction of errors.

395.8 GST/HST and Sales Tax Compliance Where Applicable. GCRI Canada shall determine whether GST/HST, sales tax, VAT, provincial tax, or other transaction taxes apply to subscriptions, training, Academy programs, publications, software access, controlled-material access, benchmarking, sponsorships, event fees, cost recovery, consulting-like services where lawful, digital services, cross-border services, grants, donations, and other receipts. Where applicable, GCRI Canada shall register, charge, collect, remit, report, exempt, zero-rate, or document treatment according to law. Public invoices and receipts shall not misstate tax treatment.

395.9 Payroll and Employment Tax Compliance Where Applicable. Where GCRI Canada has employees, officers compensated through payroll, fellows treated as employees, contractors reclassified as employees, or other taxable employment relationships, it shall comply with payroll deductions, remittances, reporting, employment tax, benefits, workers’ compensation where applicable, employment standards, records, and year-end forms. Payroll and employment tax compliance shall be integrated with worker classification review, compensation approval, reimbursement rules, stipend treatment, scholarship treatment, and contractor compliance. Misclassification risk shall be escalated.

395.10 Donation Receipt Controls Where Applicable. Donation receipts, acknowledgment receipts, charitable receipts, tax receipts, sponsorship acknowledgments, subscription invoices, fee receipts, grant acknowledgments, and in-kind contribution receipts shall be issued only where lawful, accurate, authorized, and classification-appropriate. Acknowledgment of payment shall not be represented as charitable tax receipt unless GCRI Canada has lawful authority to issue such receipt. Donation receipt controls shall distinguish donations, sponsorships, grants, subscriptions, fees, cost recovery, in-kind contributions, restricted funds, and commercial revenue.

395.11 Grant and Restricted-Fund Tax Treatment. GCRI Canada shall review grant and restricted-fund tax treatment, including whether funds are contributions, grants, service revenue, restricted revenue, deferred revenue, taxable supplies where applicable, reimbursable costs, pass-through funds, prizes, awards, stipends, scholarships, or other classifications. Treatment shall reflect substance, agreements, restrictions, deliverables, reporting, benefit to funder, public-benefit purpose, and accounting standards. Tax treatment shall not be manipulated to satisfy donor expectations, sponsor expectations, or public optics.

395.12 Sponsorship and Commercial Revenue Tax Treatment. Sponsorship, underwriting, advertising-like benefits, acknowledgments, logo placement, event visibility, training seats, subscriptions, benchmarking access, publication access, controlled-material access, and other sponsor benefits shall be reviewed for tax and accounting treatment. Sponsorship treatment shall consider whether benefits create taxable supply, commercial revenue, advertising, restricted support, or other treatment. Tax review shall not permit sponsor control, provider preference, public authority access purchase, finance-readiness purchase, certification purchase, recognition purchase, or procurement advantage.

395.13 Membership, Subscription, Training, Academy, Fellowship, and Cost-Recovery Fee Treatment. Membership fees where applicable, institutional subscriptions, individual subscriptions, training fees, Academy fees, fellowship-related fees, benchmarking subscriptions, controlled-material fees, cost-recovery fees, event fees, and program fees shall be classified and treated according to law, accounting standards, tax obligations, contractual terms, access rights, refund terms, and revenue recognition requirements. Fee treatment shall not imply governance rights, professional certification, public authority qualification, procurement eligibility, finance-readiness, recognition, maturity, provider preference, or public authority endorsement.

395.14 Cross-Border Tax Considerations. GCRI Canada shall review cross-border tax considerations where it receives funds from outside Canada, pays persons outside Canada, collaborates internationally, hosts foreign participants, provides digital access internationally, accepts foreign grants, receives foreign sponsorship, pays foreign contractors, uses foreign cloud or AI providers, or conducts activities involving multiple jurisdictions. Cross-border tax review may include withholding, sales tax, VAT, permanent establishment risk, foreign reporting, exchange controls, sanctions, export controls, and local compliance. Cross-border participation shall not be used to obscure tax obligations.

395.15 Related-Party and Private Benefit Review. Transactions involving directors, officers, members where applicable, employees, contractors, fellows, advisors, committee participants, council participants, donors, sponsors, providers, hosts, public authorities, relatives, affiliates, controlled entities, National Consortium Companies, Project SPVs, or related persons shall undergo related-party and private benefit review where material. Review shall consider fairness, reasonableness, public-benefit purpose, tax treatment, disclosure, recusal, Board approval, no-private-inurement, and records. Related-party transactions shall not be hidden in grants, sponsorships, fees, reimbursements, fellowships, or in-kind arrangements.

395.16 Tax Risk Escalation. Tax risk shall be escalated where status is uncertain, charitable language is proposed, donation receipt authority is unclear, GST/HST treatment is uncertain, payroll classification is uncertain, cross-border tax risk exists, restricted funds are misclassified, sponsorship benefits may create taxable supplies, fee treatment is unclear, related-party benefit is material, private inurement risk exists, or tax filings may be inaccurate. Escalation may include officer review, finance review, Board review, accounting advice, legal advice, correction, amended filing, revised invoice, refund, or public clarification.

395.17 Tax and Nonprofit Compliance Records. GCRI Canada shall maintain tax and nonprofit compliance records, including purpose records, nonprofit purpose compliance records, non-distribution compliance records, no-private-inurement records, non-charitable status compliance records, charitable status control records where applicable, tax filings, GST/HST and sales tax records, payroll and employment tax records where applicable, donation receipt control records, grant and restricted-fund tax treatment records, sponsorship and commercial revenue treatment records, membership / subscription / training / Academy / fellowship / cost-recovery fee treatment records, cross-border tax review records, related-party and private benefit review records, tax-risk escalation records, professional advice, corrections, amended filings, refunds, closeouts, and archives.


Section 396. Privacy Compliance

396.1 Privacy Compliance Purpose. GCRI Canada shall maintain privacy compliance to protect personal information, rights-bearing data, participant data, employee and contractor data, fellow and advisor data, community data, Indigenous data, health-sensitive data, public authority data, protected participation records, whistleblowing records, Academy records, training records, research records, controlled-room records, technical contributor records, donor and sponsor contact records, and other data subject to privacy obligations. Privacy compliance shall support lawful processing, public trust, data minimization, purpose limitation, confidentiality, security, correctionability, safeguards, and public-safe publication. Privacy compliance shall not be weakened for convenience, AI functionality, sponsor demands, provider tools, publication timelines, public authority pressure, or technical experimentation.

396.2 Canadian Privacy Law Compliance. GCRI Canada shall comply with applicable Canadian privacy laws, regulations, common law duties, contractual obligations, and recognized privacy requirements that apply to its activities, data, participants, employees, contractors, fellows, research, public authority interfaces, programs, digital tools, and publications. Where legal applicability is uncertain, GCRI Canada shall use a conservative and public-benefit-oriented privacy posture until reviewed. Canadian privacy compliance shall include collection, use, disclosure, consent or lawful basis, notice, access, correction, retention, deletion, breach response, security safeguards, cross-border transfer, and service provider controls where applicable.

396.3 Provincial and Territorial Privacy Law Compliance Where Applicable. Where GCRI Canada activities involve provincial or territorial privacy requirements, personal information, employees, contractors, public-sector entities, health information, universities, laboratories, municipalities, public authorities, hosts, research participants, communities, or local programs, GCRI Canada shall comply with applicable provincial and territorial privacy laws and requirements. Provincial and territorial privacy review shall be conducted where data location, participant location, public authority terms, health information, public-sector information, employment records, or program scope triggers local requirements.

396.4 Public Sector Privacy Requirements Where Applicable. Where GCRI Canada receives, processes, stores, analyzes, summarizes, dashboards, maps, transfers, or publishes data from public authorities or public-sector institutions, it shall comply with applicable public-sector privacy requirements, data-sharing terms, access-to-information constraints, confidentiality terms, public authority instructions, privacy impact obligations, recordkeeping requirements, and publication restrictions. Public authority data shall not be treated as freely usable merely because it comes from a public body. Public-sector privacy terms shall be recorded and carried through derived outputs.

396.5 Health Information Privacy Requirements Where Applicable. Where GCRI Canada handles health information, health-sensitive data, public health data, health-system data, disease-related data, environmental health data, clinical-adjacent data, health research data, or data concerning vulnerable health groups, it shall comply with applicable health information privacy requirements and heightened safeguards. Health information shall be subject to minimization, access limits, purpose limits, confidentiality, public-safe publication review, AI-use restrictions, retention controls, deletion controls, and breach escalation. GCRI Canada shall not provide clinical advice or public health determinations by handling health data.

396.6 Research Data Privacy Requirements. Research data involving identifiable persons, communities, small groups, sensitive attributes, public authority participants, fellows, employees, contractors, protected participants, Indigenous data, local knowledge, health-sensitive data, or vulnerable communities shall be handled according to privacy law, research ethics, consent terms, non-consent terms, withdrawal terms, community protocols, data management plans, publication limits, and correction paths. De-identification, anonymization, aggregation, masking, and suppression shall be assessed for residual re-identification risk. Research data shall not be repurposed beyond authority.

396.7 Public Authority Data Privacy Requirements. Public authority data that includes personal information, identifiable officials, identifiable community members, public program records, public health data, public safety data, public works records, infrastructure data with identifiable implications, or public-sector participation records shall be handled under public authority privacy terms and GCRI Canada privacy controls. Public authority data privacy requirements shall include lawful basis, permitted use, prohibited use, access controls, AI-use restrictions, publication restrictions, transfer restrictions, retention, deletion, correction, and breach notification.

396.8 Cross-Border Privacy Requirements. GCRI Canada shall review cross-border privacy requirements before transferring, storing, processing, accessing, publishing, or using personal information, public authority data, health-sensitive data, protected knowledge, or research data across borders or through foreign service providers. Cross-border review shall address lawful basis, notice, consent where required, contractual protections, data residency, foreign access risk, AI provider terms, cloud provider terms, subprocessors, public authority restrictions, protected knowledge safeguards, and breach response. Cross-border transfer shall be denied, restricted, localized, or controlled where risk is unacceptable.

396.9 Consent, Notice, Lawful Basis, Purpose Limitation, Minimization, Access, Correction, Deletion, Complaint, and Appeal Compliance. GCRI Canada shall maintain privacy processes for consent where required, notice where required, lawful basis, purpose limitation, minimization, access requests, correction requests, deletion requests, withdrawal requests, complaints, appeals, and response timelines. Privacy notices shall be clear, accurate, accessible, and not misleading about AI use, data sharing, publication, public authority access, cross-border transfer, retention, or correction. GCRI Canada shall collect only what is reasonably necessary for approved purposes and shall not retain or publish personal information without authority.

396.10 Privacy Impact Assessment Compliance. GCRI Canada shall conduct privacy impact assessments or equivalent privacy reviews where activities involve material personal information, public authority data, health information, AI processing, cross-border transfer, new systems, dashboards, maps, datasets, repositories, Academy platforms, controlled rooms, data rooms, public-safe publication, community participation, vulnerable persons, or high-risk data. Privacy impact assessment shall identify purpose, lawful basis, data flows, risks, safeguards, service providers, retention, deletion, publication posture, AI-use restrictions, breach response, and correction path.

396.11 Data Processor and Service Provider Privacy Controls. GCRI Canada shall ensure that data processors, service providers, cloud providers, AI providers, repository providers, data room providers, payment processors, Academy platforms, communications tools, survey tools, transcription tools, translation tools, and other vendors handling personal information are reviewed and contractually controlled where required. Controls may include processing instructions, confidentiality, security safeguards, subprocessors, cross-border transfer, AI-use restrictions, model-training prohibitions where required, breach notification, audit or assurance rights where appropriate, retention, deletion, and return.

396.12 Breach Notification Compliance. GCRI Canada shall maintain processes to assess, escalate, contain, investigate, notify, correct, and record privacy breaches. Breach notification shall be made where required by law, contract, public authority terms, health information rules, research ethics requirements, grant terms, service provider terms, or Board decision. Breach response shall include containment, evidence preservation, risk assessment, affected person assessment, public authority assessment, reporting obligations, mitigation, correction, and lessons learned. Privacy breach records shall be protected.

396.13 Privacy Training. GCRI Canada shall provide privacy training proportionate to role, access, risk, and responsibility. Training shall cover personal information, public authority data, health information, research data, consent, lawful basis, minimization, access controls, AI-use restrictions, publication risks, cross-border transfer, service provider handling, breach reporting, protected participation records, community data, protected knowledge, and public-safe publication. Training completion shall not constitute professional certification or public authority qualification.

396.14 Privacy Incident Escalation. Privacy incidents, suspected breaches, unauthorized access, unauthorized disclosure, unauthorized AI upload, unapproved transfer, public repository exposure, personal information publication, re-identification risk, health information exposure, public authority data privacy issue, protected participation exposure, or service provider breach shall be escalated promptly. Escalation may include privacy lead, officer, data / AI / cyber function, legal counsel, public authority contact, research ethics reviewer, safeguards function, Board, insurer, or regulator where required. Incident escalation shall preserve evidence and avoid premature public claims.

396.15 Privacy Compliance Records. GCRI Canada shall maintain privacy compliance records, including privacy purpose records, Canadian privacy law compliance records, provincial and territorial privacy records, public-sector privacy records, health information privacy records, research data privacy records, public authority data privacy records, cross-border privacy review records, consent / notice / lawful basis / purpose limitation / minimization / access / correction / deletion / complaint / appeal records, privacy impact assessments, processor and service provider privacy controls, breach notification records, privacy training records, privacy incident escalation records, corrections, deletions, retention records, closeouts, and archives.


Section 397. AI Governance Compliance

397.1 AI Governance Compliance Purpose. GCRI Canada shall maintain AI governance compliance to ensure that AI systems, AI assistants, machine learning tools, generative AI, retrieval systems, embeddings, vector stores, agentic systems, transcription tools, translation tools, coding assistants, model evaluation tools, simulation tools, digital twins, automated analysis, AI-assisted publication tools, and AI-enabled platforms are used lawfully, safely, transparently where required, human-accountably, data-rights-compliantly, cyber-securely, public-safe, and correctionably. AI governance compliance shall preserve GCRI Canada’s role as an evidence, methods, observability, ontology, public-good software, and open technical-baseline steward, and shall prevent AI outputs from becoming unreviewed authority, fabricated evidence, public warnings, emergency commands, finance advice, public authority decisions, procurement approvals, certifications, recognition, maturity determinations, or professional opinions.

397.2 Applicable AI Law and Policy Monitoring. GCRI Canada shall monitor applicable AI laws, regulations, standards, public-sector requirements, funder requirements, contractual obligations, research ethics requirements, privacy requirements, cybersecurity requirements, public authority terms, and internal policies relevant to its AI use. Monitoring shall include developments affecting AI risk classification, transparency, human oversight, automated decision systems, generative AI, high-impact AI systems, public-sector AI, biometric or health-adjacent AI where relevant, AI safety, data rights, model training, copyright, bias, cybersecurity, and incident reporting. Material changes shall be escalated and incorporated into policy, training, and records.

397.3 AI Risk Classification. AI uses shall be risk-classified before or during deployment according to purpose, data sensitivity, public authority relevance, public-facing status, public-safe claims risk, personal information, health information, protected knowledge, cyber sensitivity, infrastructure sensitivity, finance-sensitive evidence, model autonomy, agentic capability, decision impact, publication impact, legal impact, reputational impact, and correctionability. Risk classification shall determine approval, human review, tool restrictions, data restrictions, output limitations, monitoring, logging, incident reporting, and public disclosure where required. High-risk or uncertain uses shall be treated conservatively.

397.4 AI System Inventory and Model Register Compliance. GCRI Canada shall maintain an AI system inventory and model register for material AI systems used by or for GCRI Canada. Records shall identify system name, provider, model where known, purpose, owner, custodian, approved use, prohibited use, data classes permitted, data classes prohibited, training status, retention settings, access controls, risk classification, evaluation status, human review requirements, public-safe status, vendor terms, security review, privacy review, export-control review where applicable, and deprecation or retirement status. Unregistered AI systems shall not be used for restricted, controlled, public authority, protected knowledge, or publication-critical materials.

397.5 AI-Use Authorization Compliance. AI use shall require authorization proportionate to risk. Authorization shall identify tool, model, purpose, data class, user class, output class, storage, retention, training restrictions, publication restrictions, human review, confidentiality, security, and correction path. Unauthorized AI processing, including uploading restricted materials to public AI tools, using personal AI accounts for official records, processing public authority data through unapproved AI tools, embedding protected knowledge without permission, or using AI outputs directly in public materials without review, is prohibited.

397.6 Model Evaluation Compliance. Material AI systems shall be evaluated proportionate to their risk and use. Evaluation may include accuracy review, hallucination testing, citation testing, bias review, privacy review, data leakage testing, prompt injection testing, cyber risk review, retrieval quality review, benchmark review, output limitation review, public authority boundary review, public-safe publication review, and human usability review. Evaluation results shall be recorded and shall not be overclaimed as certification, compliance approval, public authority approval, product endorsement, or safety guarantee.

397.7 Human Review Compliance. AI-assisted outputs shall be subject to human review where they affect publications, public authority references, evidence records, methods records, technical baselines, dashboards, maps, datasets, software releases, legal-sensitive matters, finance-sensitive matters, certification-sensitive matters, procurement-sensitive matters, protected knowledge, public-safe summaries, or external communications. Human review shall verify sources, citations, reasoning, limitations, boundary language, public-safe status, confidentiality, data rights, and correction path. Human accountability remains with GCRI Canada personnel or authorized reviewers; AI shall not be treated as responsible actor.

397.8 Agentic AI Control Compliance. Agentic AI systems, automation services, autonomous tools, workflow agents, coding agents, research agents, publication agents, data agents, repository agents, communication agents, or external-action-capable systems shall be controlled before use. Controls shall include authorization, least privilege, sandboxing, action limits, approval gates, logging, credential protection, no-unapproved external communications, no-unapproved public posting, no-unapproved repository changes, no-unapproved payments, no-unapproved data transfer, no-public authority communications without approval, rollback, monitoring, and incident response. Unauthorized agent action shall be treated as an AI and cybersecurity incident.

397.9 AI Training, Fine-Tuning, Embedding, Retrieval, and Model Improvement Compliance. GCRI Canada shall not use, disclose, upload, embed, index, fine-tune, train, or permit model improvement on confidential materials, public authority data, personal information, health information, protected knowledge, community data, cyber-sensitive data, infrastructure-sensitive data, finance-sensitive evidence, restricted datasets, controlled-room materials, unpublished research, or proprietary materials unless authority, data rights, privacy review, AI-use review, security review, public authority terms, protected knowledge safeguards, and retention controls permit such use. Embeddings and retrieval indexes shall inherit the classification of the underlying materials.

397.10 AI Transparency and Disclosure Compliance Where Required. GCRI Canada shall disclose AI use where required by law, policy, funder terms, public authority terms, publication policy, research ethics, public-safe review, or reasonable public trust needs. Disclosure may identify AI assistance, human review, limitations, model class, data restrictions, and non-reliance language without disclosing sensitive system details. AI disclosure shall not be misleading and shall not imply that AI outputs are official truth, public authority determinations, finance-readiness determinations, certifications, procurement approvals, public warnings, or professional opinions.

397.11 AI Safety and Bias Review Compliance. AI systems and AI-assisted outputs shall be reviewed for safety, bias, discriminatory impact, representational harm, community harm, protected knowledge exposure, public authority misdescription, false precision, overconfidence, hallucinations, fabricated citations, unsafe instructions, cyber risk, public health risk, public safety risk, finance or insurance harm, procurement harm, and vulnerability amplification where relevant. Bias and safety review shall be heightened for vulnerable communities, Indigenous data, local knowledge, health-sensitive data, public authority data, public-facing outputs, and automated analysis.

397.12 AI Incident Reporting and Correction Compliance. AI incidents shall be reported, classified, contained, corrected, reviewed, and recorded. AI incidents include hallucinations, fabricated citations, unsafe outputs, data leakage, unauthorized access, unauthorized agent actions, bias, discriminatory outputs, drift, retrieval failure, prompt injection, public overclaim, public authority misdescription, finance overclaim, certification overclaim, procurement overclaim, recognition overclaim, or maturity overclaim. Corrections may include output withdrawal, source correction, publication correction, access revocation, tool suspension, model restriction, retraining prohibition, vendor escalation, public-safe clarification, or incident review.

397.13 AI Vendor and Third-Party Compliance. AI vendors, model providers, AI assistants, transcription providers, translation providers, coding assistants, embedding providers, retrieval providers, cloud AI services, agentic services, and AI-enabled platforms shall undergo vendor, privacy, security, data rights, AI-use, model-training, confidentiality, public authority, protected knowledge, export-control, sanctions, and contract review proportionate to risk. Vendor terms shall be recorded. AI vendors shall not receive restricted materials unless approved. GCRI Canada shall maintain exit readiness where AI vendor dependency is material.

397.14 AI Public-Safe Publication Compliance. AI-generated or AI-assisted external content shall not be published without human review and public-safe publication review where material. Review shall assess source support, citation accuracy, fabricated content, public authority references, finance-boundary language, certification-boundary language, procurement-boundary language, public warning language, emergency command language, sponsor and provider references, protected knowledge, personal information, cyber-sensitive content, infrastructure-sensitive content, and correction path. AI-generated content shall not be used as legal, financial, insurance, engineering, clinical, rating, public authority, or emergency instruction by default.

397.15 AI Governance Training. GCRI Canada shall provide AI governance training proportionate to role and risk. Training shall cover approved tools, prohibited tools, data classes, public authority data restrictions, protected knowledge restrictions, AI hallucination, fabricated citations, human review, prompt injection, retrieval limits, model training restrictions, AI incident reporting, AI public-safe publication, agentic AI controls, confidentiality, privacy, cybersecurity, and public claims boundaries. AI governance training records shall not imply professional certification or public authority qualification.

397.16 AI Governance Compliance Records. GCRI Canada shall maintain AI governance compliance records, including AI governance purpose records, AI law and policy monitoring records, AI risk classifications, AI system inventory records, model register records, AI-use authorizations, model evaluation records, human review records, agentic AI control records, AI training / fine-tuning / embedding / retrieval / model improvement compliance records, transparency and disclosure records, AI safety and bias review records, AI incident reporting and correction records, AI vendor and third-party compliance records, AI public-safe publication compliance records, AI governance training records, tool restriction records, model suspension records, deprecation records, corrections, closeouts, and archives.


Section 398. Cybersecurity Compliance

398.1 Cybersecurity Compliance Purpose. GCRI Canada shall maintain cybersecurity compliance to protect its systems, records, public-good technical assets, public authority data, research data, personal information, protected knowledge, Indigenous data, health-sensitive data, cyber-sensitive data, infrastructure-sensitive data, finance-sensitive evidence, controlled-room materials, repositories, dashboards, maps, software releases, Academy platforms, communications, and institutional continuity. Cybersecurity compliance shall support public-benefit stewardship, legal compliance, privacy compliance, public-safe publication, AI governance, public authority trust, data integrity, technical asset continuity, correctionability, and resilience. Cybersecurity shall not be optional or subordinate to convenience, publication speed, sponsor preference, provider convenience, or technical experimentation.

398.2 Cybersecurity Governance Compliance. GCRI Canada shall maintain cybersecurity governance proportionate to its size, risks, systems, data classes, public authority interfaces, technical assets, repositories, public-facing systems, controlled rooms, AI tools, and cloud environments. Governance shall include responsibility assignment, security policies, risk review, access review, incident response, vendor review, repository controls, release controls, backup and recovery controls, training, compliance monitoring, and Board or officer escalation where material. Cybersecurity governance shall be integrated with privacy, AI governance, public-safe publication, public authority data handling, and safeguards.

398.3 Security Baseline Compliance. GCRI Canada shall implement and maintain a minimum security baseline appropriate to its operations. The baseline may include asset inventory, identity and access management, MFA, least privilege, secure configuration, endpoint security, network security, cloud security, repository security, application security, data security, logging, monitoring, vulnerability management, incident response, backup, recovery, security awareness, vendor security, and secure disposal. Exceptions shall be risk-reviewed, time-limited where possible, compensated by alternate controls, and recorded.

398.4 Identity and Access Management Compliance. GCRI Canada shall maintain identity and access controls to ensure that only authorized persons access systems, repositories, data, records, controlled rooms, dashboards, maps, AI tools, cloud environments, financial systems, public authority data, protected knowledge, and publication materials. Controls shall include role-based access, least privilege, MFA where available, access approval, access review, timely offboarding, administrator controls, privileged access review, shared credential prohibition, and access logs where appropriate. Access shall be based on role and need, not status, prestige, donor relationship, sponsor relationship, provider relationship, or public authority title.

398.5 Logging and Monitoring Compliance. GCRI Canada shall maintain logging and monitoring proportionate to risk for systems, repositories, cloud environments, data rooms, controlled rooms, AI systems, dashboards, maps, identity systems, financial systems, publication systems, and sensitive data environments. Logs may record access, changes, downloads, exports, administrative actions, repository commits, release actions, AI tool usage, data transfer, failed logins, unusual behaviour, and incident indicators. Logging shall respect privacy and confidentiality while supporting accountability, incident response, and correction.

398.6 Vulnerability Management Compliance. GCRI Canada shall maintain vulnerability management for systems, software, repositories, dependencies, cloud environments, public-good technical assets, dashboards, maps, APIs, SDKs, public repositories, internal tools, and vendor systems where applicable. Vulnerability management shall include intake, classification, severity, remediation clocks, patching, compensating controls, exposure reduction, coordinated disclosure, testing, documentation, and correction. Critical vulnerabilities affecting public authority data, protected knowledge, public-facing systems, repositories, or public-good software shall be escalated promptly.

398.7 Secure Development Compliance. GCRI Canada shall maintain secure development practices for public-good software, internal software, restricted software, dashboards, maps, APIs, SDKs, schemas, test harnesses, benchmark tools, technical baselines, AI tools, and repository-based assets. Secure development may include code review, dependency review, secrets management, branch protection, vulnerability scanning, secure configuration, test coverage, negative tests, release approval, license review, SBOM practices where appropriate, and maintainer controls. Secure development compliance shall prevent public-good software from becoming an insecure public-good liability.

398.8 Repository and Release Security Compliance. Repositories and releases shall be governed by access controls, maintainer roles, branch protections, review requirements, secrets scanning, dependency controls, license checks, vulnerability checks, release notes, public-safe classification, controlled-material exclusion, public authority data exclusion, protected knowledge exclusion, AI-generated code review, and takedown or correction path. Public repositories shall not contain secrets, personal information, public authority data, protected knowledge, cyber-sensitive materials, infrastructure-sensitive materials, finance-sensitive evidence, or controlled technology unless expressly authorized and safe.

398.9 Incident Response Compliance. GCRI Canada shall maintain cybersecurity incident response processes for suspected or confirmed unauthorized access, data leakage, credential compromise, malware, ransomware, repository exposure, cloud misconfiguration, AI tool leakage, public authority data exposure, protected knowledge exposure, personal information exposure, dashboard compromise, map compromise, payment fraud, vendor breach, or public-good software vulnerability. Incident response shall include triage, containment, preservation of evidence, investigation, notification where required, remediation, public-safe communication, correction, post-incident review, and records.

398.10 Backup, Disaster Recovery, and Business Continuity Compliance. GCRI Canada shall maintain backup, disaster recovery, and business continuity controls proportionate to its systems, records, public-good technical assets, data, public authority obligations, research records, publications, repositories, controlled rooms, Academy platforms, and institutional continuity needs. Controls shall include backup requirements, encryption, restoration testing, recovery time objectives, recovery point objectives, dependency review, continuity exercises, decommissioning, successor access where lawful, and secure disposal. Backups shall be protected according to the highest relevant data classification.

398.11 Cyber-Sensitive Data Handling Compliance. Cyber-sensitive data, including vulnerability details, exploit information, incident logs, system diagrams, credentials, network information, security configurations, repository secrets, threat intelligence, penetration testing results, cyber telemetry, and security incident records, shall be access-limited, classified, encrypted where appropriate, non-public by default, and handled under secure channels. Cyber-sensitive data shall not be released publicly, uploaded to unapproved AI tools, shared with sponsors or providers, or placed in public repositories unless expressly authorized and public-safe.

398.12 Infrastructure-Sensitive Data Handling Compliance. Infrastructure-sensitive data, including critical locations, system dependencies, failure modes, maps, asset details, telemetry, control-room information, public works vulnerabilities, utility data, telecom data, energy data, water data, port data, health-system infrastructure data, cyber-physical exposures, and emergency constraints, shall be handled under heightened controls. Public-safe transformation may require aggregation, masking, delay, redaction, controlled access, public authority review, operator review, cyber review, and limitation language. Infrastructure-sensitive data shall not be published merely because it is technically available.

398.13 Public Authority Data Security Compliance. Public authority data shall be protected according to public authority terms, classification, privacy obligations, confidentiality, cybersecurity requirements, AI-use restrictions, transfer restrictions, retention requirements, and publication limits. Public authority data shall be stored only in approved systems, accessed only by authorized persons, logged where appropriate, encrypted where appropriate, and subject to incident response. GCRI Canada’s security obligations shall travel with extracts, summaries, dashboards, maps, derived outputs, backups, and archives.

398.14 Vendor Security Compliance. Vendors, service providers, cloud providers, AI providers, cybersecurity providers, repository providers, data room providers, communication platforms, payment processors, Academy platforms, survey platforms, transcription platforms, translation platforms, and other third parties shall be security-reviewed proportionate to risk. Vendor security controls may include contractual security obligations, breach notification, access controls, audit or assurance rights where appropriate, subprocessors, data residency, encryption, deletion, incident response, business continuity, and exit readiness. High-risk vendors shall be escalated.

398.15 Cybersecurity Training. GCRI Canada shall provide cybersecurity training proportionate to role and access. Training shall cover phishing, password and MFA practices, secure storage, approved tools, shadow IT prohibition, AI tool restrictions, public authority data handling, protected knowledge handling, repository security, secrets management, incident reporting, secure development, controlled-room rules, and public-safe publication risks. Training shall be renewed where risk, role, systems, or incidents warrant.

398.16 Cybersecurity Compliance Records. GCRI Canada shall maintain cybersecurity compliance records, including cybersecurity purpose records, governance records, security baseline records, identity and access management records, logging and monitoring records, vulnerability management records, secure development records, repository and release security records, incident response records, backup / disaster recovery / business continuity records, cyber-sensitive data handling records, infrastructure-sensitive data handling records, public authority data security records, vendor security records, cybersecurity training records, security exceptions, risk acceptances, remediation records, incident records, post-incident reviews, closeouts, and archives.


Section 399. Research Ethics Compliance

399.1 Research Ethics Compliance Purpose. GCRI Canada shall maintain research ethics compliance to ensure that research, evidence creation, methods development, observability work, ontology work, public-good software research, technical baseline development, public authority learning, Academy materials, fellowships, labs, challenges, benchmarking, dashboards, maps, datasets, AI-assisted analysis, scenario and simulation work, and public-safe publication are conducted with integrity, respect, safeguards, lawful authority, transparency where appropriate, consent where required, correctionability, and public-benefit fidelity. Research ethics compliance shall prevent extraction, manipulation, unsafe disclosure, sponsor-driven conclusions, provider-driven methods, public authority misuse, protected knowledge harm, community harm, AI misuse, and publication overclaim.

399.2 Research Integrity Compliance. Research integrity compliance requires source discipline, accurate citation, methods transparency where appropriate, limitation disclosure, conflict disclosure, authorship integrity, attribution integrity, negative-result capture where material, reproducibility where feasible, peer review where appropriate, data integrity, no fabrication, no falsification, no plagiarism, no fabricated citations, no misleading omission, no sponsor-controlled conclusions, no provider-controlled conclusions, and correction of errors. Research integrity shall apply to both formal research and applied evidence, methods, technical, and public-safe publication outputs.

399.3 Human-Subjects Review Compliance Where Applicable. Where GCRI Canada activities constitute or may constitute human-subjects research, participant research, interviews, surveys, behavioural observation, health-sensitive research, community research, workplace research, public authority participant research, or other research involving persons, GCRI Canada shall determine whether human-subjects review is required. Review may include research ethics board review, institutional review, community review, legal review, consent review, privacy review, safeguards review, or equivalent process. Activities shall not proceed where required review has not been completed or exemption has not been reasonably determined.

399.4 Research Ethics Board or Equivalent Review Compliance Where Applicable. Where research ethics board review, institutional review board review, university ethics review, public authority research review, community ethics review, health research review, or equivalent review is required by law, policy, agreement, funder terms, university terms, public authority terms, or research ethics standards, GCRI Canada shall obtain such review or confirm lawful exemption before conducting the relevant activity. Review conditions shall be recorded and followed. Ethics approval shall not be represented as public authority approval, certification, finance-readiness, procurement approval, or endorsement of findings.

399.5 Community Review Compliance Where Appropriate. Where research or publication affects communities, vulnerable communities, remote communities, Indigenous communities, local knowledge holders, territorial knowledge holders, cultural sites, environmental knowledge, protected knowledge, or public-safe mapping, GCRI Canada shall conduct community review where appropriate or required. Community review may address consent, non-consent, attribution, public-safe language, mapping precision, protected knowledge, risk of harm, publication timing, translation, accessibility, correction, and withdrawal. Community review shall not be tokenistic or used to manufacture legitimacy.

399.6 Indigenous, Local, Territorial, Cultural, Environmental, and Protected Knowledge Review Compliance. Research involving Indigenous data, Indigenous knowledge, local knowledge, territorial knowledge, cultural knowledge, environmental knowledge, protected knowledge, cultural sites, sacred sites, community-protected data, or custodial knowledge shall undergo safeguards review and, where applicable, Indigenous governance protocol review, FPIC review, custodial review, community review, public-safe mapping review, AI-use review, and publication review. Such knowledge shall not be converted into ordinary open data, AI training material, public maps, sponsor materials, provider materials, or technical baselines without authority and safeguards.

399.7 Health-Sensitive Research Compliance. Health-sensitive research, public health-related research, health-system research, environmental health research, disease-related research, disability-related research, vulnerable population research, or research involving health information shall comply with applicable privacy, ethics, public health, data security, consent, public-safe publication, and review requirements. Health-sensitive research outputs shall not be clinical advice, public health orders, public health warnings, treatment recommendations, or official health determinations unless separately issued by competent health authorities. Health-related outputs shall include appropriate limitations.

399.8 Vulnerable Participant Research Compliance. Research involving vulnerable participants, youth, elders, persons with disabilities, marginalized persons, displaced persons, remote communities, disaster-exposed communities, climate-exposed communities, health-vulnerable groups, infrastructure-exposed communities, protected knowledge holders, or persons at risk of retaliation shall receive heightened review. Review shall address consent, non-consent, accessibility, confidentiality, data minimization, compensation, coercion, public authority pressure, sponsor pressure, provider pressure, publication risk, AI risk, mapping risk, grievance, remedy, and withdrawal. Vulnerable participation shall not be used as symbolic legitimacy.

399.9 Consent, Non-Consent, Withdrawal, and Correction Compliance. Research activities shall comply with consent, non-consent, withdrawal, restriction, attribution, non-attribution, correction, and complaint requirements applicable to the activity. Consent shall be specific, informed, voluntary, and recorded where required. Non-consent shall be respected. Withdrawal and correction requests shall be handled according to law, ethics, protocols, agreements, data status, publication status, and public-safe obligations. Consent to one use shall not imply consent to publication, AI use, mapping, transfer, sponsor access, provider access, or future unrelated use.

399.10 Sponsor and Provider Influence Compliance. Research ethics compliance shall prevent sponsors, donors, funders, providers, hosts, public authorities, capital readers, National Consortium Companies, Project SPVs, or other actors from controlling research findings, evidence selection, methods, publication conclusions, correction decisions, negative-result handling, authorship, attribution, benchmark outcomes, challenge outcomes, public authority references, finance-readiness language, certification language, procurement language, recognition language, or maturity language. Funding or participation may define lawful scope, but not independent conclusions.

399.11 Research Conflict Compliance. Research conflicts shall be disclosed, reviewed, managed, mitigated, recused, restricted, or prohibited where material. Conflicts may involve financial interests, employment, consulting, sponsorship, provider relationships, public authority relationships, donor interests, funder interests, IP interests, publication interests, authorship interests, data access, personal relationships, institutional affiliations, National Consortium Companies, Project SPVs, or capital actors. Conflict records shall support credibility, public trust, and correctionability.

399.12 Publication Integrity Compliance. Publication integrity requires accurate authorship, attribution, source support, methods support, limitation language, public-safe review, conflict disclosure where required, sponsor and provider reference review, public authority reference review, data / AI / cyber review, safeguards review, privacy review, protected knowledge review, and correction path. Publications shall not fabricate citations, overstate confidence, omit material limitations, imply public authority approval, imply finance-readiness, imply certification, imply procurement approval, imply public warning, or imply emergency command.

399.13 Research Misconduct Review Compliance. Allegations of research misconduct shall be intaken, triaged, reviewed, investigated, corrected, and recorded. Research misconduct may include fabrication, falsification, plagiarism, fabricated citations, source manipulation, method manipulation, data manipulation, image manipulation, AI-assisted fabrication, undisclosed conflicts, sponsor-driven conclusions, provider-driven conclusions, retaliation against dissent, suppression of negative results, protected knowledge misuse, or unsafe publication. Reviews shall be fair, confidential where appropriate, conflict-controlled, and proportionate to severity.

399.14 Research Correction and Retraction Compliance. Research outputs shall remain correctionable. Corrections, supersessions, withdrawals, retractions, public clarifications, controlled notices, archive notes, dataset updates, dashboard updates, map updates, software corrections, technical baseline updates, and method revisions shall be issued where errors, omissions, misconduct, outdated sources, invalid methods, privacy issues, protected knowledge issues, public-safe issues, public authority misdescription, AI hallucination, fabricated citations, or boundary overclaims are identified. Correction shall not be blocked by sponsor, provider, donor, funder, public authority, or reputational pressure.

399.15 Research Ethics Training. GCRI Canada shall provide research ethics training proportionate to role, access, and activity. Training shall cover research integrity, source discipline, human-subjects review, consent, non-consent, withdrawal, correction, community review, Indigenous and protected knowledge safeguards, vulnerable participant safeguards, privacy, data / AI / cyber controls, sponsor and provider influence, conflicts, publication integrity, misconduct reporting, and correction. Training records shall not be represented as professional certification or public authority qualification.

399.16 Research Ethics Compliance Records. GCRI Canada shall maintain research ethics compliance records, including purpose records, research integrity records, human-subjects review records where applicable, research ethics board or equivalent review records where applicable, community review records, Indigenous / local / territorial / cultural / environmental / protected knowledge review records, health-sensitive research records, vulnerable participant research records, consent / non-consent / withdrawal / correction records, sponsor and provider influence compliance records, research conflict records, publication integrity records, misconduct review records, correction and retraction records, training records, closeouts, and archives.


Section 400. Employment, Contractor, Volunteer, Fellow, Advisor, Confidentiality, IP, Data Access, Safety, and Workplace Compliance

400.1 Employment Compliance. GCRI Canada shall comply with applicable employment law, workplace law, payroll obligations, employment standards, human rights obligations, occupational health and safety obligations, accessibility obligations, privacy obligations, tax obligations, confidentiality obligations, IP obligations, and recordkeeping requirements for employees where any. Employment compliance shall include written terms, role descriptions, compensation, benefits where applicable, expense reimbursement, supervision, training, data access, AI-use controls, cybersecurity requirements, conflicts, public statement authority, performance management, discipline, leave, accommodation, anti-harassment, anti-violence, anti-retaliation, and offboarding.

400.2 Contractor Compliance. GCRI Canada shall engage contractors through written terms appropriate to the work, classification, compensation, deliverables, confidentiality, IP, data access, AI-use controls, cybersecurity, conflicts, public statement limits, records, taxes, insurance where appropriate, safety, termination, and closeout. Contractor compliance shall include worker classification review to avoid misclassification and to ensure that contractors do not exercise officer, employee, public authority, certification, finance-readiness, procurement, or institutional authority unless separately and lawfully authorized. Contractors shall be bound by GCRI Canada’s public-benefit, non-execution, public-safe claims, and confidentiality requirements.

400.3 Consultant Compliance. Consultants shall be engaged through written terms defining scope, deliverables, authority limits, independence where relevant, conflicts, confidentiality, IP, data rights, public authority references, publication rights, AI-use restrictions, cybersecurity obligations, sponsor or provider relationships, public-safe claims boundaries, and closeout. Consultants shall not bind GCRI Canada, make public commitments, approve public authority language, issue professional opinions on behalf of GCRI Canada, provide regulated advice, direct public authorities, select providers, certify systems, or determine finance-readiness unless expressly authorized and lawful.

400.4 Volunteer Compliance. Where GCRI Canada uses volunteers, it shall define volunteer roles, supervision, training, confidentiality, data access, AI-use rules, cybersecurity obligations, IP and work product treatment, reimbursement rules, safety, conflicts, public statement limits, anti-harassment protections, non-retaliation, and offboarding. Volunteer participation shall not create employment unless law requires, shall not confer governance authority, and shall not authorize access to restricted materials without approval. Volunteers shall not be used to avoid legal obligations, exploit labour, or handle high-risk materials without safeguards.

400.5 Fellow Compliance. Fellows, research fellows, visiting fellows, technical fellows, Academy fellows, public authority fellows where lawful, community fellows where appropriate, and other fellowship participants shall be governed by fellowship agreements or equivalent records. Fellow compliance shall address scope, term, duties, stipend or support where any, scholarship or award treatment, tax treatment, confidentiality, IP, data rights, AI-use restrictions, cybersecurity, research ethics, publication rights, attribution, conflicts, public statement limits, public authority boundaries, sponsor and provider boundaries, completion, suspension, termination, and closeout. Fellowship status shall not constitute employment, professional certification, public authority qualification, or authority to bind GCRI Canada unless separately recorded.

400.6 Advisor Compliance. Advisors shall be appointed or engaged through records defining role, term, non-fiduciary status unless otherwise lawful and recorded, confidentiality, conflicts, public statement limits, output limits, data access, AI-use restrictions, cybersecurity, IP, publication review, public authority boundaries, finance boundaries, certification boundaries, procurement neutrality, and closeout. Advisor status shall not confer Board authority, officer authority, fiduciary authority, public authority status, certification authority, finance-readiness authority, procurement authority, protocol authority, or authority to bind GCRI Canada unless expressly and lawfully recorded.

400.7 Seconded Personnel Compliance. Seconded personnel, contributed staff, host-provided personnel, sponsor-provided personnel, provider-provided personnel, public authority-provided personnel, university-provided personnel, laboratory-provided personnel, or partner-provided personnel shall be governed by written terms addressing employer status, supervision, confidentiality, IP, data access, AI-use controls, cybersecurity, conflicts, public authority capacity, sponsor or provider non-control, public statement authority, safety, compensation, expenses, liability, termination, and closeout. Secondment shall not create sponsor control, provider control, public authority delegation, shared employment confusion, or authority inflation.

400.8 Written Engagement Terms. Employees, contractors, consultants, volunteers, fellows, advisors, seconded personnel, technical contributors, maintainers, trainers, reviewers, judges, and other persons acting for or with GCRI Canada shall have written engagement terms where appropriate to the role and risk. Written terms shall define purpose, scope, authority, deliverables, compensation or unpaid status, confidentiality, IP, data access, AI use, cybersecurity, conflicts, public statements, safety, harassment, discrimination, retaliation, public authority boundaries, finance boundaries, certification boundaries, procurement neutrality, termination, return of materials, and survival obligations.

400.9 Worker Classification Compliance. GCRI Canada shall classify workers accurately as employees, contractors, consultants, volunteers, fellows, advisors, seconded personnel, directors, officers, committee participants, council participants, technical contributors, maintainers, or other categories according to law and actual relationship. Classification shall consider control, integration, independence, tools, economic dependence, term, compensation, benefits, supervision, deliverables, exclusivity, and legal requirements. Misclassification risk shall be escalated and corrected. Classification shall not be manipulated for tax avoidance, employment standards avoidance, benefit avoidance, or liability avoidance.

400.10 Compensation, Reimbursement, Stipend, Scholarship, Award, and Benefit Compliance. Compensation, reimbursement, stipends, scholarships, awards, prizes, honoraria, travel support, accessibility support, fellow support, volunteer reimbursement, advisor compensation, contractor fees, and employee benefits shall be lawful, approved, documented, reasonable, tax-reviewed where appropriate, conflict-reviewed where material, and consistent with nonprofit purpose and no-private-inurement rules. Payments shall not purchase findings, public authority access, provider preference, procurement advantage, finance-readiness, certification, recognition, maturity, sponsor benefit, protected knowledge, or silence.

400.11 Confidentiality Compliance. Persons acting for or with GCRI Canada shall comply with confidentiality obligations applicable to corporate records, Board materials, committee materials, public authority materials, public authority data, personal information, health-sensitive information, research records, cyber-sensitive data, infrastructure-sensitive data, finance-sensitive evidence, protected knowledge, controlled-room materials, data-room materials, donor and sponsor information, vendor information, legal materials, employment records, whistleblowing records, and non-public publications. Confidentiality obligations shall survive role termination where required. Unauthorized disclosure shall be escalated and corrected.

400.12 Intellectual Property and Work Product Compliance. GCRI Canada shall ensure that intellectual property and work product created by employees, contractors, consultants, fellows, volunteers, advisors, technical contributors, maintainers, grantees, partners, sponsored work participants, and seconded personnel are governed by appropriate assignment, license, waiver, consent, moral rights treatment, contributor license agreement, open-source terms, background IP terms, foreground IP terms, attribution, confidentiality, publication rights, and repository rules. IP compliance shall preserve public-good technical assets, open technical baselines, public-good software, correctionability, and chain of title.

400.13 Data Access Compliance. Data access shall be granted only to persons with approved role, need, authority, training, confidentiality, cybersecurity readiness, AI-use compliance, public authority capacity where relevant, protected knowledge authorization where relevant, and records. Data access shall be role-based, least-privilege, time-limited where appropriate, logged where appropriate, reviewed periodically, and revoked upon role change or offboarding. Access shall not be granted because of seniority, donor status, sponsor status, provider status, public authority title, media interest, or capital-reader interest.

400.14 AI-Use and Cybersecurity Compliance. Persons acting for or with GCRI Canada shall use only approved AI tools, systems, repositories, storage, communication channels, cloud environments, collaboration tools, and cybersecurity practices for GCRI Canada work. They shall not upload restricted materials to unapproved AI systems, use personal drives for official records, place confidential data in public repositories, share credentials, bypass MFA, export data without permission, use shadow IT, or automate external actions without authorization. Violations shall be treated as compliance and security matters.

400.15 Workplace Health, Safety, Accessibility, Harassment, Violence, and Anti-Retaliation Compliance. GCRI Canada shall maintain workplace health, safety, accessibility, anti-harassment, anti-violence, non-discrimination, accommodation, and anti-retaliation compliance for employees and, as appropriate, contractors, volunteers, fellows, advisors, participants, community members, and others interacting with GCRI Canada. Workplace compliance shall cover physical, remote, hybrid, digital, event, controlled-room, Academy, lab, challenge, field, and community contexts. GCRI Canada shall not tolerate harassment, intimidation, retaliation, discrimination, unsafe conditions, accessibility exclusion, or abuse of authority.

400.16 Onboarding, Training, Supervision, Performance, Discipline, and Offboarding Compliance. GCRI Canada shall maintain onboarding, role-based training, supervision, performance, discipline, corrective action, role change, access review, and offboarding processes proportionate to role and risk. Onboarding shall include confidentiality, conflicts, data / AI / cyber, public authority boundaries, finance boundaries, certification boundaries, procurement neutrality, public-safe publication, safeguards, protected participation, and records. Offboarding shall include access revocation, return or deletion of materials, repository access removal, device and account handling, confidentiality reminders, IP closeout, data disposition, public statement limits, and records.

400.17 Employment and Personnel Compliance Records. GCRI Canada shall maintain employment and personnel compliance records, including employment compliance records, contractor records, consultant records, volunteer records, fellow records, advisor records, seconded personnel records, written engagement terms, worker classification records, compensation / reimbursement / stipend / scholarship / award / benefit records, confidentiality records, IP and work product records, data access records, AI-use and cybersecurity compliance records, workplace health / safety / accessibility / harassment / violence / anti-retaliation records, onboarding records, training records, supervision records, performance records, discipline records, offboarding records, access revocation records, corrections, investigations, closeouts, and archives.

Section 401. Sanctions Screening

401.1 Sanctions Screening Purpose. GCRI Canada shall maintain sanctions screening controls to ensure that its funds, programs, data access, technology access, public-good technical assets, public authority interfaces, research collaborations, Academy activities, fellowships, controlled rooms, repositories, sponsorships, grants, donations, subscriptions, payments, in-kind contributions, and Nexus-compatible activities are not used to support, facilitate, benefit, evade restrictions for, or transact with sanctioned, restricted, prohibited, high-risk, or otherwise legally impermissible persons, entities, jurisdictions, transactions, or activities. Sanctions screening shall protect GCRI Canada’s legal compliance, institutional integrity, public-benefit purpose, nonprofit posture, public authority trust, public-good asset stewardship, controlled technology discipline, and correctionability.

401.2 Persons Subject to Screening. GCRI Canada may screen persons and entities where legally required, contractually required, risk-appropriate, or necessary to protect GCRI Canada’s public-benefit purpose. Persons subject to screening may include donors, sponsors, funders, providers, vendors, contractors, consultants, partners, hosts, public authority-linked entities where appropriate, members where any, subscribers, fellows, advisors, employees, volunteers, technical contributors, maintainers, grantees, award recipients, challenge participants, controlled-room participants, data-room participants, Academy participants, public-good software contributors, repository users with privileged access, and persons receiving payments, access, benefits, or controlled materials.

401.3 Donor Screening. Donors may be screened before acceptance, renewal, public acknowledgment, restricted-fund use, major gift acceptance, in-kind acceptance, public authority-facing use, or program association. Donor screening shall assess sanctions, restricted-party status, jurisdictional risk, beneficial ownership where appropriate, source-of-funds concerns, reputational risk, anti-capture risk, public authority sensitivity, controlled technology risk, corruption risk, human rights risk, and inconsistency with GCRI Canada’s public-benefit purpose. GCRI Canada may refuse, restrict, return, or terminate donor support where screening identifies unacceptable risk.

401.4 Sponsor Screening. Sponsors may be screened before sponsorship acceptance, benefit activation, logo use, program association, event participation, public acknowledgment, controlled-room access, Academy seat allocation, challenge support, benchmarking involvement, or public authority-facing reference. Sponsor screening shall assess sanctions, restricted-party status, ownership and control, jurisdiction, sector sensitivity, public authority exposure, provider-neutrality risk, procurement risk, finance-boundary risk, controlled technology risk, corruption risk, reputation risk, and support-without-control. Sponsorship shall not proceed where sanctions or restriction risk cannot be resolved.

401.5 Funder Screening. Funders, grantors, philanthropic institutions, public funders, development funders, corporate funders, program funders, underwriters, and restricted-fund providers may be screened before acceptance or renewal. Funder screening shall assess legal permissibility, restricted-party status, jurisdictional restrictions, public authority-linked risk, grant condition risk, export-control risk, source-of-funds concerns, donor-advised or intermediary structures where material, and whether funding conditions could require unlawful dealings, prohibited transfers, controlled technology access, public authority misdescription, or regulated-perimeter drift.

401.6 Provider and Vendor Screening. Providers and vendors may be screened before procurement, contracting, access grant, public acknowledgment, technical integration, repository access, data processing, cloud deployment, AI provider use, cybersecurity engagement, data room use, public-good software dependency, or public authority-facing participation. Screening shall assess restricted-party status, ownership and control, jurisdiction, export-control risk, controlled technology sensitivity, cybersecurity risk, sanctions exposure, supply-chain risk, public authority restrictions, and whether the provider or vendor may lawfully receive funds, data, technology, access, or references.

401.7 Contractor and Consultant Screening. Contractors and consultants may be screened before engagement, payment, controlled access, public authority-facing work, research access, data access, repository access, controlled technology exposure, public-good asset contribution, public-safe publication work, or international collaboration. Screening shall assess restricted-party status, jurisdiction, affiliation, public authority restrictions, export-control sensitivity, cybersecurity access risk, confidentiality risk, data access risk, conflict risk, and lawful ability to perform the work. Screening shall not replace worker classification, conflict review, confidentiality terms, or IP controls.

401.8 Partner and Host Screening. Partners and hosts, including universities, laboratories, public institutions, community institutions, public authorities where appropriate, facilities, event hosts, lab hosts, data-room hosts, infrastructure hosts, technical testbed hosts, and international partners, may be screened before engagement. Screening shall assess restricted-party status, jurisdiction, legal status, public authority sensitivity, sanctions exposure, controlled technology exposure, data access risk, protected knowledge risk, human rights risk, corruption risk, reputation risk, cybersecurity risk, and whether the relationship could create prohibited support, public authority confusion, or unsafe transfer.

401.9 Public Authority and State-Linked Entity Screening Where Appropriate. Public authorities, state-owned enterprises, Crown entities, public institutions, public universities, public laboratories, utilities, public infrastructure operators, foreign public bodies, development finance bodies, and other state-linked entities may be screened where risk, law, funder terms, export controls, sanctions programs, controlled technology, public-sector sensitivity, or cross-border engagement warrants. Screening shall not imply distrust of lawful public authorities; it shall ensure that public-benefit engagement does not violate restrictions, controlled technology rules, national security controls, or public-sector limitations.

401.10 Participant, Member, Fellow, Advisor, Contributor, and Controlled-Room Access Screening Where Appropriate. Participants, members where any, fellows, advisors, technical contributors, maintainers, reviewers, judges, Academy participants, challenge participants, controlled-room participants, data-room participants, repository users, and other persons may be screened where access to restricted data, controlled technology, public authority data, protected knowledge, cyber-sensitive materials, infrastructure-sensitive materials, finance-sensitive evidence, or restricted programs warrants screening. Screening shall be proportionate, lawful, non-discriminatory, privacy-aware, and tied to risk, access, payment, or legal obligations.

401.11 Jurisdiction Screening. GCRI Canada shall screen jurisdictions where transactions, collaborations, participants, payments, data transfers, technology transfers, controlled-room access, repository access, cloud processing, AI processing, research activity, public authority engagement, or publication may involve restricted, sanctioned, embargoed, high-risk, or controlled jurisdictions. Jurisdiction screening shall consider nationality, residence, incorporation, place of operations, source of funds, data location, access location, cloud region, export destination, re-export risk, and indirect access. Jurisdictional risk may require denial, restriction, geo-fencing, local storage, redaction, re-scoping, or legal review.

401.12 Transaction Screening. Transactions shall be screened where sanctions, restricted-party, anti-corruption, export-control, controlled technology, public-sector sensitivity, or financial crime risk may exist. Transactions include donations, grants, sponsorships, subscriptions, fees, reimbursements, stipends, scholarships, awards, prizes, procurement, vendor payments, contractor payments, refunds, in-kind contributions, data transfers, technology transfers, repository access, controlled-room access, software releases, cloud access, and public-good technical asset sharing. GCRI Canada shall not complete a transaction where legal restrictions prohibit it or where risk remains unresolved.

401.13 Payment Screening. Payments to or from GCRI Canada may be screened before receipt, acceptance, processing, refund, reimbursement, transfer, award, stipend, scholarship, contractor payment, vendor payment, grant disbursement, prize payment, or other financial movement. Payment screening shall assess payer, payee, intermediary, bank, jurisdiction, currency, source, purpose, restrictions, red flags, and beneficial ownership where appropriate. Payments may be held, rejected, returned, restricted, reported, or escalated where screening indicates sanctions, evasion, corruption, fraud, restricted-party, or jurisdictional risk.

401.14 Data Transfer and Technology Transfer Screening. Data transfers and technology transfers may be screened where public authority data, controlled technology, AI models, AI weights, software, cryptography, cyber tools, AI-RAN / O-RAN materials, DePIN materials, geospatial data, satellite or remote-sensing data, robotics or drone data, quantum-adjacent materials, advanced compute methods, semiconductor-relevant materials, infrastructure-sensitive data, or protected knowledge may be transferred, disclosed, exported, re-exported, accessed, downloaded, or made available. Screening shall include recipient, jurisdiction, access method, purpose, license need, restrictions, and public-safe handling.

401.15 Screening Frequency. Screening may occur at onboarding, acceptance, renewal, payment, access grant, transaction, publication, transfer, material change, red-flag event, restricted-party list update, jurisdiction change, ownership change, program change, incident, public authority request, contract amendment, or closeout. Higher-risk relationships may require recurring screening. GCRI Canada may adopt screening thresholds and intervals proportionate to risk, legal requirements, public authority terms, funder terms, controlled technology exposure, and data sensitivity. Screening results shall not be treated as permanent where facts may change.

401.16 Hit Escalation, False Positive Resolution, Denial, Restriction, Reporting, and Recordkeeping. Potential sanctions hits, restricted-party matches, ownership concerns, jurisdiction concerns, payment concerns, transaction concerns, or transfer concerns shall be escalated for review before proceeding. GCRI Canada shall resolve false positives through reasonable evidence, document the basis for resolution, and prohibit use of informal assurances where risk remains material. Confirmed or unresolved hits may result in denial, restriction, payment hold, access suspension, transaction cancellation, return of funds, contract termination, transfer prohibition, reporting where required, legal review, Board escalation, or public-safe correction. Records shall be protected and retained.

401.17 Sanctions Screening Records. GCRI Canada shall maintain sanctions screening records, including screening purpose records, persons screened, donor screening records, sponsor screening records, funder screening records, provider and vendor screening records, contractor and consultant screening records, partner and host screening records, public authority and state-linked entity screening records where applicable, participant / member / fellow / advisor / contributor / controlled-room screening records where applicable, jurisdiction screening records, transaction screening records, payment screening records, data transfer and technology transfer screening records, screening frequency records, hit escalation records, false positive resolution records, denial records, restriction records, reporting records where required, legal review records, Board review records, corrections, closeouts, and archives.


Section 402. Export Controls and Controlled Technology Review

402.1 Export-Control Purpose. GCRI Canada shall maintain export-control and controlled technology review to ensure that software, data, AI models, AI weights, cryptography, cyber tools, telecom materials, AI-RAN, O-RAN, sensors, robotics, drones, autonomous systems, satellite, remote-sensing, geospatial, Earth observation, quantum-adjacent, semiconductor, advanced manufacturing, sovereign compute, secure enclave, dual-use, infrastructure-sensitive, and other controlled or sensitive technologies are not exported, re-exported, transferred, disclosed, published, accessed, or released in violation of applicable law, contractual obligations, public authority terms, national security requirements, sanctions, or institutional safeguards. Export-control compliance shall preserve public-good work without confusing openness with unrestricted release.

402.2 Controlled Technology Review. GCRI Canada shall review whether technology, software, technical data, source code, schematics, models, model weights, datasets, documentation, technical assistance, know-how, test harnesses, benchmarks, dashboards, maps, APIs, SDKs, architectures, methods, or controlled annexes are controlled, restricted, dual-use, public-sector sensitive, national-security-sensitive, export-sensitive, or otherwise subject to access controls. Controlled technology review shall occur before public release, repository access, controlled-room access, foreign person access where applicable, international collaboration, cloud processing, AI provider use, data transfer, publication, or technical assistance.

402.3 Software Export Review. Software, including public-good software, internal software, restricted software, APIs, SDKs, scripts, automation tools, AI tools, cybersecurity tools, observability tools, dashboard code, map code, simulation code, test harnesses, benchmark tools, and technical baseline implementations, shall be reviewed for export-control issues where risk is present. Review shall consider functionality, encryption, cyber capability, dual-use potential, controlled technical content, destination, user, license, repository visibility, dependencies, build artifacts, release notes, and whether public release would constitute export or re-export.

402.4 Data Export Review. Data, datasets, telemetry, public authority data, infrastructure-sensitive data, cyber-sensitive data, geospatial data, Earth observation data, satellite data, remote-sensing data, health-sensitive data, protected knowledge, AI training data, benchmark data, model evaluation data, and derived outputs shall be reviewed for export-control, sanctions, data residency, public authority, privacy, controlled technology, and public-safe restrictions before cross-border transfer, foreign access, cloud processing, publication, repository placement, dashboard release, map release, or controlled-room access. Data export review shall include derived and aggregated outputs where re-identification or sensitivity remains.

402.5 AI Model and Weight Export Review. AI models, model weights, fine-tuned models, adapters, embeddings, vector stores, retrieval indexes, prompts, system instructions, evaluation sets, agent configurations, synthetic datasets, model cards, system cards, and AI governance artifacts shall be reviewed where they may contain controlled technology, sensitive data, public authority data, protected knowledge, cyber-sensitive content, infrastructure-sensitive content, or dual-use capability. Model and weight release shall consider access class, hosted access, download restrictions, destination, user, license, misuse risk, safeguards, and legal advice where required.

402.6 Cryptography Export Review. Cryptographic software, encryption tools, key management tools, secure communication methods, secure enclave materials, cryptographic protocols, post-quantum cryptography materials, authentication systems, signing tools, secure logging tools, and documentation may require export-control or legal review before release, transfer, access, or publication. Review shall assess whether the material is public, open-source, mass-market, research, controlled, restricted, or otherwise subject to licensing or notification requirements. Cryptography public-good purposes shall not eliminate export-control review.

402.7 Cyber Tool Export Review. Cybersecurity tools, vulnerability scanners, exploit-detection tools, penetration testing tools, incident response tools, malware analysis tools, threat intelligence methods, red-team tools, defensive tools with offensive potential, proof-of-concept code, vulnerability details, repository security tooling, and cyber telemetry methods shall be reviewed for export-control, sanctions, misuse, public-safe publication, and controlled-access concerns. Cyber tool review shall distinguish defensive literacy from transferable offensive capability and may require redaction, controlled release, delayed disclosure, recipient restrictions, or denial.

402.8 Telecom, AI-RAN, O-RAN, Sensor, Robotics, Drone, Autonomous System, Satellite, Geospatial, Earth Observation, Quantum-Adjacent, Semiconductor, Advanced Manufacturing, and Dual-Use Export Review. GCRI Canada shall conduct export-control review for telecom, AI-RAN, O-RAN, sensor, robotics, drone, autonomous system, satellite, geospatial, Earth observation, remote-sensing, quantum-adjacent, post-quantum-relevant, semiconductor, advanced manufacturing, industrial control, secure compute, and dual-use materials where applicable. Review shall assess technical content, destination, end user, end use, public authority sensitivity, national security sensitivity, infrastructure sensitivity, controlled technology, data sensitivity, software capability, hardware capability, and whether release could enable misuse, surveillance, cyber-physical harm, or restricted transfer.

402.9 Public Release as Possible Export. GCRI Canada shall treat public release as a possible export where software, data, technical documentation, model weights, cryptographic material, cyber tools, geospatial data, satellite imagery, controlled methods, infrastructure-sensitive information, or dual-use technology may become available globally. Public release may occur through websites, reports, whitepapers, datasets, public dashboards, public maps, repositories, software releases, papers, presentations, Academy materials, social media, public-safe summaries, or public technical baselines. Public-good intent shall not excuse unlawful release.

402.10 Repository Access as Possible Export. Repository access may constitute export, re-export, disclosure, technical assistance, or controlled access depending on content, user, jurisdiction, and permissions. GCRI Canada shall classify repositories, branches, issues, pull requests, artifacts, packages, releases, secrets, build outputs, documentation, and maintainer access before granting access. Public repositories shall undergo release review; private repositories shall undergo access review. Foreign access, contributor access, and provider access may require screening, restriction, redaction, geo-fencing, or legal review.

402.11 Controlled-Room Access as Possible Export. Controlled-room, data-room, no-download-room, secure review-room, public authority room, public finance reader room, cyber-sensitive room, infrastructure-sensitive room, protected knowledge room, or technical annex access may constitute controlled technology disclosure or export depending on participant identity, jurisdiction, citizenship or residency where applicable, affiliation, access location, and material class. Access shall be reviewed, limited, logged where appropriate, and conditioned on confidentiality, no-download, no-redistribution, AI-use restrictions, and closeout obligations.

402.12 Foreign Person Access Review Where Applicable. Where applicable law, contract, public authority terms, controlled technology rules, national security requirements, or funding terms require foreign person access review, GCRI Canada shall review whether access by non-Canadian persons, foreign nationals, foreign entities, foreign affiliates, foreign-located persons, or persons subject to foreign control may constitute an export or controlled disclosure. Review shall be lawful, proportionate, privacy-aware, non-discriminatory within legal limits, and tied to controlled technology or restricted data. Access may be denied, restricted, supervised, redacted, or licensed where required.

402.13 License, Permit, Exemption, or Legal Advice Review Where Required. Where export-control, controlled technology, sanctions, national security, cryptography, cyber, geospatial, satellite, AI, telecom, dual-use, public authority, or contractual issues are uncertain or material, GCRI Canada shall obtain legal advice, determine whether a license, permit, authorization, exemption, exception, notification, classification, or government approval is required, and document the result before proceeding. Activities requiring authorization shall not proceed until authorization is obtained or the activity is re-scoped to remove the requirement. Informal assumptions shall not substitute for review.

402.14 Denial, Restriction, Geo-Fencing, Access Limitation, Redaction, or Re-Scoping. GCRI Canada may deny, restrict, geo-fence, access-limit, redact, delay, generalize, aggregate, mask, remove, quarantine, reclassify, re-scope, or withdraw technology, data, software, documentation, model artifacts, dashboards, maps, repositories, publications, controlled-room materials, or collaborations to comply with export controls, sanctions, national security obligations, public authority terms, privacy, protected knowledge safeguards, or public-safe publication requirements. Denial or restriction shall be recorded and shall not be treated as improper exclusion where legally or safely required.

402.15 Export-Control Training. GCRI Canada shall provide export-control and controlled technology training proportionate to role and risk. Training shall cover controlled technology categories, public release risk, repository access risk, controlled-room access risk, foreign person access review where applicable, data transfer, technology transfer, AI model and weight transfer, cryptography, cyber tools, geospatial data, AI-RAN / O-RAN materials, dual-use issues, sanctions interactions, public-good software releases, and escalation. Training records shall not create professional certification.

402.16 Export-Control Records. GCRI Canada shall maintain export-control records, including export-control purpose records, controlled technology reviews, software export reviews, data export reviews, AI model and weight export reviews, cryptography export reviews, cyber tool export reviews, telecom / AI-RAN / O-RAN / sensor / robotics / drone / autonomous system / satellite / geospatial / Earth observation / quantum-adjacent / semiconductor / advanced manufacturing / dual-use export reviews, public release review records, repository access review records, controlled-room access review records, foreign person access review records where applicable, license / permit / exemption / legal advice records, denial records, restriction records, geo-fencing records, access limitation records, redaction records, re-scoping records, training records, incidents, corrections, closeouts, and archives.


Section 403. Sensitive AI, AI-RAN, DePIN, Cyber, Sovereign Compute, Cryptography, Geospatial, Earth Observation, Robotics, Drones, Autonomous Systems, Telecom, Quantum-Adjacent, and Dual-Use Controls

403.1 Controlled Technology Categories. GCRI Canada shall identify and control sensitive technology categories that may create public safety, public authority, national security, cyber, infrastructure, export-control, sanctions, privacy, protected knowledge, public-safe publication, procurement, finance-boundary, or reputational risks. Controlled technology categories may include sensitive AI, agentic AI, AI-RAN, O-RAN, DePIN, DLT, cyber tools, sovereign compute, secure enclaves, cryptography, geospatial systems, Earth observation, satellite and remote-sensing systems, robotics, drones, autonomous systems, sensors, telecom, critical infrastructure systems, quantum-adjacent technologies, post-quantum-relevant systems, semiconductors, advanced manufacturing, industrial systems, supply-chain technologies, and dual-use systems.

403.2 Sensitive AI Controls. Sensitive AI controls shall apply to AI systems capable of generating high-impact outputs, processing sensitive data, supporting public authority-facing materials, influencing public-safe publication, analyzing public authority data, handling protected knowledge, generating code, supporting cyber analysis, creating geospatial or infrastructure outputs, or producing finance-sensitive, certification-sensitive, procurement-sensitive, public warning-sensitive, or professional-boundary-sensitive outputs. Controls may include risk classification, approved tool use, human review, data restrictions, model evaluation, hallucination testing, bias review, transparency where required, access limits, logging, incident response, and correction.

403.3 Agentic AI Controls. Agentic AI controls shall apply to AI systems that can take actions, call tools, modify repositories, send communications, access external systems, retrieve data, automate workflows, interact with public systems, manage files, write code, perform analysis, or affect records. Agentic systems shall be sandboxed, permission-limited, approval-gated, logged, monitored, and prohibited from unauthorized payments, public posting, public authority communications, data transfers, repository changes, credential use, deletion, external commitments, or controlled-material disclosure. Unauthorized agent action shall trigger incident response.

403.4 AI-RAN Controls. AI-RAN-related materials, including AI-native radio access network concepts, telecom edge intelligence, radio optimization methods, sensing-adjacent methods, network automation methods, AI-RAN evidence methods, deployment patterns, testbeds, datasets, dashboards, and technical baselines, shall be reviewed for telecom sensitivity, critical infrastructure sensitivity, cyber risk, export-control risk, provider-neutrality risk, public authority boundary risk, procurement implication, and public-safe publication. GCRI Canada shall not certify AI-RAN systems, approve telecom deployments, direct network operations, or create procurement preference by AI-RAN evidence work.

403.5 O-RAN Controls. O-RAN-related materials, including open radio access network architectures, interfaces, software, test methods, integration profiles, interoperability materials, security findings, vendor comparisons, deployment notes, and public-good baselines, shall be reviewed for cybersecurity, telecom sensitivity, export controls, provider neutrality, procurement neutrality, public authority boundaries, and public-safe release. O-RAN support by GCRI Canada shall remain evidence, methods, literacy, public-good software, or baseline stewardship and shall not constitute certification, conformance approval, vendor selection, telecom regulatory approval, or procurement approval.

403.6 DePIN and DLT Controls. DePIN, DLT, blockchain, Web3, tokenized infrastructure, decentralized identity, proof systems, decentralized storage, decentralized compute, data markets, and related systems shall be reviewed for data rights, cyber risk, privacy, public authority implications, finance-boundary risk, securities risk, token implication, public claims, provider neutrality, infrastructure sensitivity, sanctions, jurisdiction, and public-safe publication. GCRI Canada shall not issue investment advice, token endorsements, securities determinations, finance-readiness determinations, public authority approvals, or procurement preferences through DePIN or DLT-related work.

403.7 Cyber Tool Controls. Cyber tool controls shall govern tools, scripts, methods, datasets, playbooks, exploit-adjacent materials, vulnerability reports, incident response methods, detection logic, red-team materials, threat intelligence, and cyber training materials. Controls shall distinguish public-safe defensive knowledge from actionable offensive capability. Materials may require controlled access, delayed disclosure, responsible disclosure, redaction, export-control review, public authority coordination, vulnerability handling, and repository restrictions. Cyber tools shall not be marketed as certification, security guarantee, or public authority approval.

403.8 Sovereign Compute and Secure Enclave Controls. Sovereign compute, secure enclave, confidential computing, trusted execution environment, high-performance compute, AI compute, data localization, controlled compute, and secure processing materials shall be reviewed for data residency, public authority requirements, privacy, cybersecurity, export controls, vendor dependency, national security sensitivity, public finance boundary, provider neutrality, and public-safe claims. GCRI Canada may support evidence, methods, baselines, literacy, and public-good architecture, but shall not approve sovereign compute procurements, guarantee security, underwrite finance, certify infrastructure, or operate public authority systems by default.

403.9 Cryptography Controls. Cryptography controls shall govern encryption, authentication, key management, signing, zero-knowledge methods, secure communications, secure logging, post-quantum methods, cryptographic libraries, and cryptographic documentation. Controls shall address export review, security review, implementation risk, public-good software release, dependency risk, vulnerability disclosure, public-safe publication, and correction. GCRI Canada shall not imply that cryptographic materials are certified, legally compliant for all users, procurement-approved, export-cleared, or security-guaranteed unless separately and lawfully determined.

403.10 Geospatial and Earth Observation Controls. Geospatial and Earth observation materials, including maps, layers, coordinates, satellite imagery, remote-sensing data, terrain data, infrastructure overlays, environmental indicators, hazard maps, cultural site data, protected knowledge, public health data, public safety data, and community vulnerability maps, shall be reviewed for public-safe release, protected knowledge, geospatial precision, infrastructure sensitivity, public authority terms, export controls, privacy, re-identification, public warning implication, and harm risk. Controls may require masking, aggregation, delay, redaction, no-public-release, or controlled access.

403.11 Satellite and Remote-Sensing Controls. Satellite and remote-sensing data, products, analytics, imagery, derived indicators, tasking-related information, sensor metadata, geolocation data, and Earth observation outputs shall be reviewed for export controls, licensing, public authority terms, national security sensitivity, infrastructure sensitivity, environmental sensitivity, protected knowledge, public-safe publication, and public warning implications. GCRI Canada shall not use satellite or remote-sensing outputs as official warnings, emergency commands, regulatory determinations, public authority decisions, procurement approvals, finance-readiness determinations, or infrastructure guarantees.

403.12 Robotics, Drones, Autonomous Systems, and Sensor Controls. Robotics, drones, autonomous systems, sensors, edge devices, telemetry systems, and related datasets or software shall be reviewed for safety, public authority permissions, aviation or transport requirements where applicable, privacy, surveillance risk, cyber risk, data rights, geospatial sensitivity, controlled technology, export controls, public-safe publication, and community safeguards. GCRI Canada shall not operate regulated systems, direct autonomous deployments, issue safety approvals, approve procurement, or assume public authority or operator functions unless separately lawful and expressly authorized.

403.13 Telecom and Critical Infrastructure Controls. Telecom and critical infrastructure materials shall be controlled to prevent exposure of vulnerabilities, dependencies, control logic, network maps, security architecture, sensitive locations, failure modes, public safety communications constraints, public works vulnerabilities, utility vulnerabilities, port vulnerabilities, energy vulnerabilities, water vulnerabilities, health-system vulnerabilities, cyber-physical risks, and public authority-sensitive information. Public-safe publication shall be conservative where misuse risk is material. GCRI Canada shall not become operator, regulator, certifier, procurement body, public warning body, or emergency commander.

403.14 Quantum-Adjacent and Post-Quantum-Relevant Controls. Quantum-adjacent and post-quantum-relevant materials, including quantum computing, quantum sensing, quantum communications, post-quantum cryptography, quantum-relevant security analysis, quantum simulation, and quantum-adjacent risk methods, shall be reviewed for dual-use sensitivity, export controls, cryptographic implications, national security sensitivity, public authority implications, provider neutrality, and public-safe publication. GCRI Canada may support literacy, evidence, methods, and baseline work while avoiding overclaims of readiness, certification, public authority approval, or security guarantees.

403.15 Semiconductor, Advanced Manufacturing, Industrial, and Supply Chain Controls. Semiconductor, advanced manufacturing, industrial control, supply-chain, additive manufacturing, materials, robotics, automation, and production-system materials shall be reviewed for controlled technology, export controls, sanctions, national security sensitivity, public authority terms, provider neutrality, procurement implications, cyber-physical risk, infrastructure sensitivity, and public-safe publication. GCRI Canada shall not create supplier preference, procurement approval, manufacturing approval, export clearance, investment recommendation, or industrial certification by technical baseline, benchmark, or public-safe output.

403.16 Dual-Use Review. Dual-use review shall assess whether materials, methods, software, datasets, models, tools, architectures, benchmarks, dashboards, maps, or technical assistance may support both public-benefit and harmful, military, surveillance, cyber-offensive, infrastructure-disruptive, public safety-threatening, export-controlled, or otherwise sensitive uses. Dual-use review may require redaction, access restriction, publication delay, controlled-room treatment, legal review, safeguards review, public authority consultation where appropriate, or denial. Public-good intent shall not eliminate dual-use risk.

403.17 Sensitive Publication and Repository Controls. Sensitive publications and repositories shall be reviewed before release for controlled technology, cyber-sensitive details, infrastructure-sensitive data, geospatial risk, protected knowledge, public authority data, sanctions, export controls, privacy, AI misuse, provider neutrality, procurement implication, finance-boundary implication, and public-safe status. Release controls may include staged release, restricted repository access, branch separation, private security advisories, vulnerability disclosure, redacted public reports, controlled annexes, license restrictions where lawful, and takedown procedures.

403.18 Sensitive Collaboration and Access Controls. Sensitive collaborations and access shall be governed by screening, role classification, need-to-know, confidentiality, access logs where appropriate, no-download restrictions where appropriate, AI-use restrictions, export-control review, sanctions review, public authority terms, protected knowledge safeguards, cyber review, infrastructure sensitivity review, and closeout. Sensitive access shall not be granted because of sponsor status, donor status, provider relationship, public authority title, capital-reader interest, academic prestige, or media interest. Access may be revoked where risk changes.

403.19 Sensitive Technology Incident Response. Sensitive technology incidents shall be reported, contained, investigated, corrected, and recorded. Incidents may include unauthorized access, unauthorized export, unauthorized repository release, controlled technology disclosure, cyber-sensitive disclosure, infrastructure-sensitive disclosure, AI model leakage, data leakage, protected knowledge disclosure, public authority data exposure, cryptographic vulnerability release, exploit release, sanctions issue, or public-safe publication failure. Response may include access revocation, repository takedown, public-safe correction, controlled notice, legal review, public authority notice where required, and Board escalation.

403.20 Controlled Technology Records. GCRI Canada shall maintain controlled technology records, including controlled technology category records, sensitive AI controls, agentic AI controls, AI-RAN controls, O-RAN controls, DePIN and DLT controls, cyber tool controls, sovereign compute and secure enclave controls, cryptography controls, geospatial and Earth observation controls, satellite and remote-sensing controls, robotics / drones / autonomous systems / sensor controls, telecom and critical infrastructure controls, quantum-adjacent and post-quantum-relevant controls, semiconductor / advanced manufacturing / industrial / supply-chain controls, dual-use reviews, sensitive publication and repository controls, sensitive collaboration and access controls, sensitive technology incident response records, corrections, restrictions, denials, closeouts, and archives.


Section 404. Competition / Antitrust, Market Sensitivity, Clean Teams, Clean Rooms, Benchmarking, Indices, Comparative Outputs, and Do-Not-Discuss Lists

404.1 Competition and Antitrust Purpose. GCRI Canada shall maintain competition and antitrust discipline to ensure that its public-benefit programs, councils, committees, working groups, benchmarks, indices, market baseline libraries, capability maps, challenge programs, labs, Academy sessions, controlled rooms, clean rooms, provider forums, sponsor forums, public authority learning sessions, curated introductions, and Nexus-compatible interfaces are not used for price coordination, bid coordination, market allocation, customer allocation, output restriction, provider exclusion, procurement steering, boycott, collusive strategy, anticompetitive information exchange, or competition-sensitive conduct. GCRI Canada’s public-good role shall not be used as a safe harbor for improper market coordination.

404.2 Market-Conduct Compliance. Participants shall comply with applicable competition and antitrust laws and GCRI Canada market-conduct rules. Market-conduct compliance shall apply to providers, vendors, sponsors, donors, funders, hosts, partners, competitors, public authorities, universities, laboratories, National Consortium Companies, Project SPVs, consultants, capital actors, and other participants. GCRI Canada shall structure agendas, materials, data intake, discussions, benchmarking, and outputs to avoid anticompetitive conduct. Participants remain responsible for their own compliance.

404.3 Meeting Discipline. Meetings involving market actors, competitors, providers, sponsors, procurement-sensitive actors, public authorities, or capital actors shall use appropriate agenda discipline, chairing, participation rules, do-not-discuss reminders where warranted, attendance records, conflict controls, clean-room procedures where required, and stop-meeting authority. Discussions shall remain tied to public-benefit learning, evidence, methods, technical baselines, public-safe publication, safeguards, interoperability, research, or governance. Off-agenda competition-sensitive discussions shall be stopped, corrected, and recorded where material.

404.4 Council and Working Group Discipline. Councils, advisory bodies, working groups, competence cells, drafting groups, expert panels, model review panels, peer review bodies, benchmarking groups, and technical groups shall not be used to coordinate market behaviour. Chairs and stewards shall maintain scope, agenda, records, conflict management, provider-neutrality, procurement-neutrality, public authority-boundary discipline, and do-not-discuss controls. Technical collaboration shall not become commercial coordination, vendor exclusion, bid strategy, market allocation, or procurement steering.

404.5 Benchmarking Compliance. Benchmarking programs shall be designed and administered to avoid anticompetitive information exchange. Benchmarking compliance may require aggregation, de-identification, historical data rules, independent administration, clean-team handling, clean-room access, minimum participant thresholds, no participant-specific disclosure, no future pricing, no customer-specific data, no bid-specific data, no provider-exclusion outputs, and legal review where needed. Benchmarks shall not be used as ratings, certification, procurement approvals, finance-readiness determinations, or provider preferences.

404.6 Index and Comparative Output Compliance. Indices, comparative outputs, market baselines, technical comparisons, capability maps, maturity-adjacent summaries, public-safe comparative notes, or performance summaries shall be reviewed for competition, procurement, provider-neutrality, public authority, finance-boundary, certification-boundary, and public claims risk. Comparative outputs shall be evidence-based, limitation-bearing, public-safe, and correctionable. They shall not be designed or used to exclude providers, coordinate purchasing, manipulate markets, imply official rankings, or create procurement advantage.

404.7 Market Baseline Library Compliance. Market baseline libraries shall be maintained as public-benefit evidence and learning resources, not as market coordination tools. Market baseline libraries may include aggregated information, technical categories, public sources, anonymized trends, public-safe summaries, neutral taxonomies, and historical baselines where appropriate. They shall not contain or expose competitively sensitive pricing, margins, bid strategies, future plans, customer allocations, market allocation plans, provider exclusion lists, or procurement instructions. Library access and outputs shall be governed by classification and correction.

404.8 Clean-Team Use. Clean teams may be used where competitively sensitive information must be collected, reviewed, normalized, aggregated, or analyzed without exposing it to competitors, market participants, sponsors, providers, public authorities, or other restricted persons. Clean teams shall be appointed, trained, confidentiality-bound, access-limited, conflict-reviewed, and independent enough for the intended purpose. Clean-team outputs shall be aggregated, de-identified, limitation-bearing, and reviewed before release. Clean-team access shall not confer provider preference or procurement advantage.

404.9 Clean-Room Use. Clean rooms may be used to permit controlled analysis of sensitive data, market-sensitive information, public authority data, provider data, benchmark data, infrastructure data, or technical data while preventing unauthorized disclosure, download, copying, AI upload, participant-specific exposure, or collusive use. Clean-room rules shall define access, permitted use, prohibited use, logging, data export, outputs, review, de-identification, aggregation, retention, deletion, and closeout. Clean-room participation shall not imply certification, finance-readiness, procurement approval, or public authority approval.

404.10 Aggregation and De-Identification. Aggregation and de-identification shall be used where needed to prevent disclosure of competitively sensitive, participant-specific, provider-specific, customer-specific, bid-specific, price-specific, or market-sensitive information. Aggregation shall be sufficient to prevent reverse engineering where risk is material. De-identification shall account for small sample sizes, unique providers, specialized markets, public authority contexts, geography, timing, and combination with public sources. Aggregated outputs shall remain correctionable and limitation-bearing.

404.11 Independent Administration. Benchmarking, indices, market baseline libraries, comparative outputs, clean rooms, clean teams, and market-sensitive processes may require independent administration by GCRI Canada personnel, external administrators, legal counsel, technical stewards, or neutral reviewers. Independent administration shall prevent provider capture, sponsor capture, public authority procurement influence, participant-specific disclosure, selective benefit, and manipulation of results. Administrators shall follow recorded rules and shall not use their role for private advantage.

404.12 Competitively Sensitive Information Controls. Competitively sensitive information includes current or future prices, margins, costs, bids, bid strategy, customer lists, customer allocation, sales strategy, market allocation, production capacity, output plans, procurement strategy, supplier strategy, confidential commercial terms, contract terms, product roadmaps where market-sensitive, salaries where competition-sensitive, strategic plans, or other information that could facilitate coordination. Such information shall not be discussed, collected, shared, or published except under lawful, controlled, necessary, and reviewed conditions.

404.13 Do-Not-Discuss List. GCRI Canada may maintain do-not-discuss lists for meetings, programs, councils, working groups, benchmarking, clean rooms, provider forums, sponsor forums, public authority rooms, and market-sensitive activities. Do-not-discuss items may include prices, future pricing, discounts, margins, costs, bids, tenders, customer allocation, market allocation, supplier allocation, boycotts, provider exclusion, output restriction, procurement strategy, investment strategy, insurance terms, lending terms, wage coordination, commercially sensitive roadmaps, and collusive strategy. Chairs may restate the list at the beginning of sessions.

404.14 No Price, Margin, Cost, Bid, Customer, Market Allocation, Boycott, Exclusion, Procurement Steering, or Collusive Strategy Discussion. No participant shall use GCRI Canada activities to discuss, agree, signal, coordinate, invite, or facilitate price, margin, cost, bid, customer, market allocation, boycott, exclusion, procurement steering, collusive strategy, output restriction, wage coordination, supplier allocation, or other anticompetitive conduct. If such discussion occurs or appears likely, GCRI Canada shall stop the discussion, redirect, record the incident where material, and escalate if required. Repeated or serious violations may result in removal or termination.

404.15 Stop-Meeting Authority. The chair, officer, legal counsel, compliance lead, program owner, committee steward, clean-room administrator, or any authorized person may stop, pause, adjourn, or redirect a meeting where competition or antitrust risk arises. Any participant may raise a good-faith concern. Stop-meeting authority shall be exercised without retaliation. Restart may occur only after the discussion is re-scoped, sensitive information is removed, legal or compliance review is obtained where needed, and meeting discipline is restored.

404.16 Competition Incident Escalation. Competition incidents, suspected anticompetitive discussion, unauthorized sharing of competitively sensitive information, benchmark misuse, clean-room breach, clean-team breach, procurement steering, provider exclusion, bid coordination, price signalling, or collusive conduct shall be escalated promptly. Escalation may include officer review, legal review, Board review, participant notice, access restriction, output correction, meeting termination, program suspension, public-safe clarification, or reporting where required. Records shall be protected and retained.

404.17 Competition Training. GCRI Canada shall provide competition and antitrust training proportionate to role and risk for persons involved in provider-facing activities, sponsor-facing activities, benchmarking, market baseline libraries, comparative outputs, public authority rooms, procurement-sensitive contexts, clean rooms, clean teams, councils, working groups, challenges, labs, and curated introductions. Training shall cover do-not-discuss rules, market-sensitive information, clean-room discipline, benchmarking safeguards, stop-meeting authority, provider neutrality, procurement neutrality, and escalation.

404.18 Competition and Antitrust Records. GCRI Canada shall maintain competition and antitrust records, including competition purpose records, market-conduct compliance records, meeting discipline records, council and working group discipline records, benchmarking compliance records, index and comparative output compliance records, market baseline library compliance records, clean-team records, clean-room records, aggregation and de-identification records, independent administration records, competitively sensitive information control records, do-not-discuss lists, no-price / margin / cost / bid / customer / market allocation / boycott / exclusion / procurement steering / collusive strategy records, stop-meeting records, incident escalation records, training records, corrections, restrictions, removals, closeouts, and archives.


Section 405. Procurement Neutrality

405.1 Procurement Neutrality Purpose. GCRI Canada shall maintain procurement neutrality to ensure that its research, evidence, methods, observability, ontology, public-good software, open technical baselines, public-safe publications, Academy programs, competence cells, benchmarking, capability mapping, curated introductions, public authority learning, dashboards, maps, labs, challenges, adoption windows, replication sprints, governed pilots, and Nexus-compatible interfaces do not become procurement instruments, vendor-selection mechanisms, public procurement shortcuts, provider endorsements, tender specifications, or purchasing recommendations. Procurement neutrality shall preserve public trust, public authority boundaries, provider neutrality, competition compliance, sponsor non-control, and GCRI Canada’s non-executing role.

405.2 No Public Procurement Authority. GCRI Canada shall not hold or exercise public procurement authority unless a separate lawful instrument expressly and validly confers a defined role, and such role is reviewed and approved under this Bylaw. By default, GCRI Canada is not a public procurement body, purchasing authority, tender evaluator, prequalification body, vendor approval body, procurement agent, procurement advisor, or public authority buyer. Public authorities and purchasers remain solely responsible for their own procurement laws, requirements, decisions, and records.

405.3 No Vendor Selection for Public Authorities. GCRI Canada shall not select vendors, providers, contractors, technologies, platforms, cloud providers, AI providers, cybersecurity providers, telecom providers, AI-RAN providers, O-RAN providers, DePIN providers, software providers, data providers, consultants, National Consortium Companies, Project SPVs, or other market actors for public authorities. Capability mapping, curated introductions, benchmarking, technical baselines, evidence notes, public-safe summaries, and learning sessions shall not be represented as vendor selection. Any lawful purchaser must make its own selection independently.

405.4 No Bid Evaluation by Default. GCRI Canada shall not evaluate bids, score tenders, rank proposals, approve bidders, design procurement scoring, provide procurement evaluation committees, or participate in public procurement decisions by default. Technical evidence, methods, baselines, or public-safe materials may be educational or informational only unless a separate lawful engagement expressly permits a defined, non-conflicted, legally reviewed role. Even where technical input is provided, GCRI Canada shall avoid certification, endorsement, provider preference, and procurement approval language.

405.5 No Procurement Recommendation. GCRI Canada shall not recommend that any public authority, host, sponsor, donor, funder, provider, partner, community, National Consortium Company, Project SPV, or other person procure, buy, lease, subscribe to, select, deploy, integrate, or prefer any provider, technology, product, service, platform, software, cloud service, AI system, cybersecurity tool, telecom system, AI-RAN solution, O-RAN solution, DePIN solution, sensor system, dashboard, map, or technical solution. Neutral technical information may be provided with limitations and correction path.

405.6 No Procurement Preference by Research Participation. Participation in GCRI Canada research, evidence development, methods development, studies, pilots, labs, publications, peer review, technical baselines, software development, public-safe summaries, or data contribution shall not confer procurement preference. Research participation shall not be marketed as prequalification, approved vendor status, public authority approval, technical approval, procurement readiness, finance-readiness, certification, recognition, maturity, or Nexus-compatible procurement advantage. Research outputs shall include boundary language where procurement misunderstanding is possible.

405.7 No Procurement Preference by Sponsorship. Sponsorship, donation, underwriting, in-kind support, cloud credits, compute credits, software support, event support, Academy support, challenge support, benchmark support, scholarship support, or public-good infrastructure support shall not confer procurement preference or purchasing advantage. Sponsors shall not receive procurement access, tender influence, public authority access purchase, provider preference, public authority quote leverage, benchmark advantage, or technical baseline influence as a sponsor benefit. Sponsor materials shall be reviewed for procurement overclaim.

405.8 No Procurement Preference by Provider Contribution. Provider contributions, including code, data, software, hardware, expertise, staff time, funding, in-kind support, technical assistance, training, challenge participation, benchmark participation, lab participation, or technical baseline comments, shall not confer procurement preference. Provider contributions may be acknowledged factually but shall not be represented as endorsement, preferred status, certification, public authority approval, technical approval, recognition, maturity, finance-readiness, or procurement readiness.

405.9 No Procurement Preference by Technical Baseline Use. Use of GCRI Canada technical baselines, schemas, APIs, SDKs, ontology files, reference architectures, test harnesses, evidence profiles, observability profiles, AI governance profiles, cybersecurity profiles, public-good software, or public-safe publication materials shall not confer procurement preference, compliance approval, certification, conformance approval, public authority adoption, or vendor prequalification. Technical baseline use may support interoperability, learning, evidence discipline, and public-good architecture only. Purchasers remain responsible for their own requirements and procurement decisions.

405.10 No Procurement Preference by Nexus-Compatible Claim. No claim of Nexus-compatible participation, Nexus-compatible interface, Nexus Observatory relevance, Nexus Grid evidence input, Nexus Rails technical evidence input, GRA-facing technical input, GRF-compatible process input, Academy participation, competence-cell training, challenge award, benchmark inclusion, public-safe publication, or GCRI Canada collaboration shall confer procurement preference. Nexus-compatible language shall be controlled and shall not be used as vendor-selection shorthand, public authority approval, finance-readiness, certification, recognition, maturity, or procurement status.

405.11 Public Authority Procurement Boundary Language. GCRI Canada shall include procurement boundary language in public authority-facing, provider-facing, sponsor-facing, public, benchmark, challenge, capability-mapping, curated-introduction, technical baseline, dashboard, map, and public-safe materials where procurement misunderstanding is reasonably possible. Such language shall state that GCRI Canada does not approve vendors, recommend procurement, evaluate bids, certify providers, determine public authority purchasing eligibility, or replace lawful procurement processes. Boundary language shall be clear, proximate, and proportionate to risk.

405.12 Provider and Sponsor Claim Review. Provider and sponsor claims involving GCRI Canada participation, support, contribution, funding, acknowledgment, technical baseline use, Academy participation, benchmark involvement, challenge outcomes, lab participation, public authority presence, Nexus-compatible references, public-safe summaries, or public-good software shall be reviewed where GCRI Canada becomes aware of procurement-risk language. GCRI Canada may require correction, withdrawal, revised language, removal of logos, removal of public authority references, suspension of benefits, access revocation, or termination where claims imply procurement advantage.

405.13 Correction of Procurement Overclaim. GCRI Canada shall correct procurement overclaims promptly and proportionately. Procurement overclaims include statements that GCRI Canada approval, participation, evidence, methods, baseline use, benchmark inclusion, challenge award, Academy completion, public authority attendance, public authority data contribution, sponsor support, provider contribution, or Nexus-compatible claim creates vendor approval, procurement approval, prequalification, preferred provider status, tender eligibility, purchasing recommendation, public authority endorsement, finance-readiness, certification, recognition, maturity, or compliance approval. Correction may be public-safe or controlled according to audience and risk.

405.14 Procurement Neutrality Records. GCRI Canada shall maintain procurement neutrality records, including procurement neutrality purpose records, no-public-procurement-authority records, no-vendor-selection records, no-bid-evaluation-by-default records, no-procurement-recommendation records, no-procurement-preference-by-research-participation records, no-procurement-preference-by-sponsorship records, no-procurement-preference-by-provider-contribution records, no-procurement-preference-by-technical-baseline-use records, no-procurement-preference-by-Nexus-compatible-claim records, procurement boundary language records, provider and sponsor claim review records, procurement overclaim correction records, public authority notices where appropriate, withdrawals, access restrictions, closeouts, and archives.


406.1 Professional Boundary Purpose. GCRI Canada shall maintain professional boundary controls to ensure that its research, evidence, methods, observability, ontology, public-good software, technical baselines, publications, dashboards, maps, Academy materials, public authority learning, public-safe summaries, proof packs, technical evidence inputs, benchmarks, labs, challenges, and Nexus-compatible interfaces are not misused or misunderstood as regulated professional opinions or services. GCRI Canada’s default role is non-executing, public-benefit, evidence-based, method-governed, public-safe, and correctionable. Professional boundary controls shall prevent unauthorized legal, engineering, clinical, investment, insurance, accounting, rating, emergency, public authority, procurement, or other regulated opinions.

406.2 No Legal Opinion by Default. GCRI Canada shall not provide legal opinions, legal advice, regulatory opinions, statutory interpretations, compliance opinions, contract opinions, procurement legal opinions, public authority legal opinions, tax legal opinions, securities legal opinions, privacy legal opinions, export-control legal opinions, or enforceability opinions by default. Legal context may be discussed for literacy or boundary purposes with appropriate limitations. Any legal opinion, if ever provided, shall require authorized qualified counsel, lawful engagement, clear scope, conflict review, records, and appropriate disclaimers.

406.3 No Engineering Opinion by Default. GCRI Canada shall not provide regulated engineering opinions, professional engineering certifications, infrastructure safety approvals, structural approvals, telecom engineering approvals, energy system approvals, water system approvals, cyber-physical system approvals, AI-RAN / O-RAN deployment approvals, robotics or drone safety approvals, digital twin operational approvals, or engineering sign-offs by default. Engineering-adjacent outputs shall remain evidence, methods, learning, technical baseline, or public-safe artifacts unless a lawful qualified professional engagement expressly provides otherwise.

406.4 No Clinical Opinion by Default. GCRI Canada shall not provide clinical opinions, medical advice, diagnostic advice, treatment recommendations, triage instructions, public health clinical determinations, health-system operating instructions, patient-specific guidance, or clinical risk determinations by default. Health-related research, public health literacy, health-system resilience learning, environmental health evidence, or health-sensitive data review shall be limitation-bearing and shall not substitute for medical, clinical, public health, or health authority judgment.

406.5 No Investment Opinion by Default. GCRI Canada shall not provide investment opinions, investment advice, securities advice, portfolio advice, valuation opinions, investment suitability determinations, capital allocation recommendations, securities offerings, solicitation, brokerage, finder services, capital placement, underwriting advice, bankability determinations, investability determinations, finance-readiness determinations, or transaction recommendations by default. Technical evidence inputs and proof pack literacy shall be non-reliance, public-benefit, limitation-bearing, and correctionable. Capital actors remain responsible for their own decisions.

406.6 No Insurance Opinion by Default. GCRI Canada shall not provide insurance opinions, underwriting opinions, insurability determinations, insurance-readiness determinations, premium advice, coverage advice, claims advice, risk-transfer advice, insurance placement, broker services, actuarial opinions, or insurance approval by default. Risk evidence, resilience indicators, scenarios, dashboards, maps, public-safe summaries, and technical evidence may support literacy only and shall not be represented as insurance advice or underwriting support unless separately lawful and authorized.

406.7 No Accounting or Tax Opinion by Default. GCRI Canada shall not provide accounting opinions, audit opinions, assurance opinions, tax opinions, charitable receipting opinions for third parties, revenue recognition advice for others, valuation opinions, financial statement opinions, or tax compliance opinions by default. Its own accounting and tax compliance may be supported by qualified professionals. External materials discussing finance, tax, accounting, nonprofit, or grant treatment shall be limitation-bearing and shall not substitute for qualified professional advice.

406.8 No Rating Opinion by Default. GCRI Canada shall not provide ratings, credit ratings, public finance ratings, insurance ratings, ESG ratings, safety ratings, cybersecurity ratings, provider ratings, maturity ratings, resilience ratings, investment ratings, bankability ratings, certification ratings, or official rankings by default. Benchmarks, indices, scoreboards, maturity-adjacent language, evidence classifications, dashboards, and public-safe comparative outputs shall not be represented as ratings or official determinations. Any rating-like activity would require separate lawful authority, independence, conflicts controls, methodology, limitations, and Board approval.

406.9 No Public Health Order or Medical Advice by Default. GCRI Canada shall not issue public health orders, medical advice, disease warnings, contamination warnings, isolation directions, quarantine directions, vaccination directives, health advisories, health emergency measures, clinical protocols, or official health determinations by default. Public health-related participation, dashboards, maps, simulations, evidence outputs, or public-safe summaries shall include limitations and direct users to competent health authorities where appropriate.

406.10 No Emergency Management Order by Default. GCRI Canada shall not issue emergency management orders, evacuation instructions, shelter instructions, emergency alerts, dispatch directions, responder commands, operational resource allocations, infrastructure restoration orders, cyber response directives, public safety orders, or emergency communications by default. Scenario, simulation, Observatory, Truth Engine, dashboard, and map materials shall not be treated as emergency command. Emergency authority remains with competent public authorities and operators.

406.11 No Public Authority Legal Interpretation by Default. GCRI Canada shall not provide official public authority legal interpretations, regulatory interpretations, procurement interpretations, public finance interpretations, public safety interpretations, public health interpretations, public works interpretations, or statutory interpretations on behalf of public authorities by default. Public authority learning, regulator-listening discussions, and public authority references shall not be converted into official legal positions. Public authorities must issue their own interpretations through lawful processes.

406.12 Professional Opinion Only by Authorized Qualified Person Under Lawful Engagement and Clear Scope. A professional opinion may be provided only where a qualified person authorized by law is engaged under a lawful and clear scope, with conflict review, client or audience identification, reliance limitations, professional standards, insurance where appropriate, records, and Board or officer approval where required. Such opinion shall be separated from GCRI Canada’s general public-benefit outputs and shall not expand GCRI Canada’s default role. Professional opinions shall not be implied through informal statements, titles, presentations, dashboards, maps, technical baselines, or public authority discussions.

406.13 Required Disclaimer and Limitation Language. GCRI Canada shall include disclaimer and limitation language where professional-boundary misunderstanding is reasonably possible. Such language shall state, as applicable, that GCRI Canada outputs are not legal advice, engineering opinion, clinical advice, investment advice, insurance advice, accounting advice, tax advice, rating, procurement approval, public authority decision, public warning, emergency command, certification, finance-readiness determination, public finance approval, or regulated professional opinion. Disclaimers shall be clear and proximate where risk is material.

406.14 Professional Boundary Escalation. Professional-boundary concerns shall be escalated where a document, dashboard, map, report, evidence pack, proof pack, technical baseline, Academy material, public authority learning material, sponsor material, provider material, donor report, public communication, controlled-room discussion, or participant statement appears to provide or imply regulated professional advice or opinion. Escalation may include legal review, qualified professional review, public-safe publication review, withdrawal, correction, revised disclaimer, access restriction, training, or Board review.

406.15 Professional Boundary Records. GCRI Canada shall maintain professional boundary records, including professional boundary purpose records, no-legal-opinion records, no-engineering-opinion records, no-clinical-opinion records, no-investment-opinion records, no-insurance-opinion records, no-accounting-or-tax-opinion records, no-rating-opinion records, no-public-health-order-or-medical-advice records, no-emergency-management-order records, no-public-authority-legal-interpretation records, authorized qualified professional opinion records where any, disclaimer and limitation language records, escalation records, corrections, withdrawals, closeouts, and archives.


Section 407. Risk Management System

407.1 Risk Management Purpose. GCRI Canada shall maintain a risk management system to identify, assess, monitor, mitigate, escalate, record, and correct risks that may affect its legal compliance, public-benefit purpose, corporate governance, nonprofit posture, tax compliance, privacy, AI governance, cybersecurity, research integrity, evidence and methods integrity, public authority boundaries, finance boundaries, procurement neutrality, certification boundaries, provider neutrality, sponsor non-control, protected knowledge, community safeguards, public-safe publication, continuity, reputation, strategy, and Nexus role separation. Risk management shall be forward-looking, evidence-based, proportionate, and correctionable.

407.2 Board Oversight of Risk. The Board shall oversee GCRI Canada’s risk management system and shall ensure that material risks are brought to the Board or appropriate committee in a timely, structured, and record-supported manner. Board oversight shall include review of risk appetite, high-risk activities, boundary incidents, public authority-sensitive matters, finance-sensitive matters, data / AI / cyber incidents, research integrity concerns, sanctions and export-control issues, competition issues, protected knowledge matters, insurance coverage, major third-party dependencies, capture risks, and serious compliance breaches. Board oversight shall not replace management ownership of day-to-day risk controls.

407.3 Management Responsibility for Risk. Officers, management, program owners, data / AI / cyber leads, safeguards leads, research leads, finance personnel, publication approvers, repository custodians, controlled-room custodians, Academy leads, and other responsible persons shall identify, assess, control, escalate, and document risks within their roles. Management shall ensure that risks are not hidden, minimized, deferred, or reframed as public-relations issues where they are legal, safety, integrity, compliance, public authority, finance-boundary, data, AI, cyber, or safeguards risks. Material risk uncertainty shall be escalated.

407.4 Risk Appetite. GCRI Canada may adopt risk appetite statements defining the level and type of risk it is willing to accept in pursuit of its public-benefit purpose. Risk appetite shall be conservative for legal compliance, public authority delegation, public warning, emergency command, public finance, investment advice, certification, procurement approval, sanctions, export controls, cybersecurity, privacy, protected knowledge, community harm, research integrity, and improper private benefit. GCRI Canada may accept measured operational, innovation, research, and program risk only where controlled, mission-aligned, record-supported, and correctionable.

407.5 Risk Taxonomy. GCRI Canada shall maintain a risk taxonomy or equivalent classification structure to organize material risks. The taxonomy may include legal risk, governance risk, research integrity risk, evidence and methods risk, data / AI / cyber / privacy risk, public authority boundary risk, finance / insurance / securities / lending / underwriting / rating / public finance / procurement / certification boundary risk, sponsor / donor / provider / host / partner / capture risk, community safeguards and protected knowledge risk, operational and continuity risk, reputational risk, strategic risk, tax risk, sanctions risk, export-control risk, competition risk, workplace risk, and public-safe publication risk.

407.6 Legal Risk. Legal risk includes risk of breach of corporate law, nonprofit law, tax law, privacy law, AI-related law, cybersecurity obligations, employment law, contractor law, research ethics requirements, sanctions, export controls, competition law, procurement law, securities law, insurance law, public authority law, contract law, IP law, data protection law, accessibility law, human rights law, or other legal obligations. Legal risk shall be escalated for counsel review where material, uncertain, or high-impact.

407.7 Governance Risk. Governance risk includes risks relating to Board authority, officer authority, member rights where applicable, conflicts, recusals, records, minutes, delegations, committee authority, advisory role confusion, legal separateness, shared liability, role confusion with other Nexus institutions, unauthorized commitments, informal governance, capture, mission drift, and failure to preserve nonprofit and non-executing posture. Governance risk shall be addressed through records, training, Board oversight, authority matrices, and correction.

407.8 Research Integrity Risk. Research integrity risk includes fabrication, falsification, plagiarism, fabricated citations, source manipulation, method manipulation, data manipulation, undisclosed conflicts, sponsor influence, provider influence, public authority pressure, selective publication, suppression of negative results, AI hallucination, unsafe extrapolation, false precision, and failure to correct. Research integrity risk shall be managed through review, source discipline, methods discipline, conflict controls, publication integrity, peer review where appropriate, and correction.

407.9 Evidence and Methods Risk. Evidence and methods risk includes inaccurate evidence, stale evidence, unsupported claims, weak source lineage, missing limitations, flawed methodology, unreproducible outputs, invalid benchmarks, invalid dashboards, misleading maps, invalid models, untested assumptions, poor ontology alignment, semantic drift, inadequate uncertainty handling, and misuse of technical baselines. Evidence and methods risk shall be addressed through evidence records, method records, validation, peer review where appropriate, limitation language, versioning, and correctionability.

407.10 Data, AI, Cyber, and Privacy Risk. Data, AI, cyber, and privacy risk includes unauthorized data use, data leakage, privacy breach, public authority data misuse, protected knowledge exposure, unapproved AI use, hallucinations, prompt injection, model drift, unauthorized agent actions, cyber incident, repository exposure, credential compromise, insecure cloud configuration, data processor failure, and public-safe publication failure. These risks shall be managed through classification, approved tools, security controls, AI governance, privacy controls, incident response, vendor review, and training.

407.11 Public Authority Boundary Risk. Public authority boundary risk includes risk that GCRI Canada engagement is misunderstood as public authority delegation, official adoption, endorsement, public warning, emergency command, regulatory approval, procurement approval, funding approval, public finance approval, public-private partnership, sovereign obligation, public policy adoption, public infrastructure adoption, or official public authority decision. Boundary risk shall be controlled through capacity classification, approved public language, reference controls, non-endorsement language, data contribution records, and correction.

407.12 Finance, Insurance, Securities, Lending, Underwriting, Rating, Public Finance, Procurement, and Certification Boundary Risk. This boundary risk includes risk that GCRI Canada outputs are understood as investment advice, securities offering, solicitation, brokerage, finder activity, capital placement, insurance placement, underwriting, lending approval, guarantee, rating, bankability, finance-readiness, insurance-readiness, public finance approval, procurement approval, vendor selection, certification, accreditation, compliance approval, recognition, maturity, or provider preference. Controls shall include non-reliance language, professional-boundary discipline, procurement neutrality, finance-boundary review, certification-boundary review, and correction.

407.13 Sponsor, Donor, Provider, Host, Partner, and Capture Risk. Capture risk includes risk that external supporters, providers, hosts, partners, donors, funders, sponsors, public authorities, universities, laboratories, capital actors, National Consortium Companies, Project SPVs, or related parties influence governance, research agenda, findings, methods, publications, public authority access, technical baselines, software, benchmarks, challenges, Academy programs, corrections, or Nexus interface outputs. Capture risk shall be managed through influence caps, concentration review, aggregation review, conflict controls, support-without-control, provider neutrality, and Board escalation.

407.14 Community Safeguards and Protected Knowledge Risk. Community safeguards and protected knowledge risk includes risk of extraction, tokenism, unsafe mapping, protected knowledge exposure, Indigenous rights harm, local or territorial knowledge misuse, cultural site disclosure, environmental knowledge misuse, retaliation, accessibility failure, non-consent violation, withdrawal failure, correction failure, community stigmatization, sponsor or provider misuse, public authority misuse, or AI inference harm. Controls shall include safeguards review, consent pathways, non-consent respect, public-safe mapping, do-no-harm controls, grievance, remedy, and stop-work authority.

407.15 Operational and Continuity Risk. Operational and continuity risk includes risk of system failure, personnel dependency, vendor dependency, funding interruption, records loss, repository loss, cyber incident, cloud outage, program failure, legal default, insurance gap, governance gap, key-person dependency, data loss, backup failure, disaster recovery failure, public-good asset abandonment, and loss of institutional memory. Controls shall include business continuity, backup, disaster recovery, succession planning, documentation, access management, vendor exit readiness, and archive discipline.

407.16 Reputational Risk. Reputational risk includes risk to public trust, institutional credibility, public authority trust, community trust, research credibility, donor trust, sponsor trust, provider neutrality, and Nexus-compatible legitimacy arising from overclaims, inaccuracies, conflicts, public authority confusion, public-safe failures, protected knowledge harm, cyber incidents, data breaches, finance-boundary drift, procurement implication, certification implication, sponsor capture, provider preference, or failure to correct. Reputational risk shall be treated as a consequence of substantive risk, not as a reason to hide substantive issues.

407.17 Strategic Risk. Strategic risk includes mission drift, expansion beyond capacity, role confusion, over-extension, excessive dependency on one funder or provider, misalignment with Nexus role separation, loss of public-benefit focus, uncontrolled commercialization, technology overreach, public authority over-proximity, finance-boundary drift, failure to maintain technical relevance, and failure to sustain public-good assets. Strategic risk shall be reviewed by the Board and management in connection with planning, budgets, programs, partnerships, and major initiatives.

407.18 Risk Review Cycle. GCRI Canada shall review risks periodically and upon material events, including new programs, major funding, major public authority engagement, new data classes, new AI tools, new controlled technology, new jurisdictions, new providers, major publications, incidents, complaints, audits, legal changes, tax changes, public authority requests, export-control issues, sanctions updates, or strategic changes. Risk reviews shall identify changes, controls, residual risk, responsible persons, mitigation, deadlines, and escalation.

407.19 Risk Management Records. GCRI Canada shall maintain risk management records, including risk management purpose records, Board oversight records, management responsibility records, risk appetite records, risk taxonomy records, legal risk records, governance risk records, research integrity risk records, evidence and methods risk records, data / AI / cyber / privacy risk records, public authority boundary risk records, finance / insurance / securities / lending / underwriting / rating / public finance / procurement / certification boundary risk records, sponsor / donor / provider / host / partner / capture risk records, community safeguards and protected knowledge risk records, operational and continuity risk records, reputational risk records, strategic risk records, risk review cycle records, mitigations, residual risk records, escalations, closeouts, and archives.


Section 408. Risk Register, Issue Register, Control Register, KRIs, KPIs, Risk Appetite, Three Lines Model, and Segregation of Duties

408.1 Risk Register. GCRI Canada may maintain a risk register identifying material risks, owners, categories, causes, consequences, likelihood, impact, inherent risk, controls, residual risk, risk appetite alignment, mitigation actions, due dates, escalation status, Board reporting status, and closeout. The risk register shall support governance, management, compliance, public authority boundary discipline, finance-boundary discipline, data / AI / cyber discipline, safeguards, and correctionability. The register may be scaled to GCRI Canada’s maturity and resources but shall be sufficiently reliable for serious institutional oversight.

408.2 Issue Register. GCRI Canada may maintain an issue register identifying actual issues, incidents, breaches, control failures, delays, unresolved findings, audit recommendations, legal notices, privacy concerns, AI incidents, cyber incidents, research integrity issues, safeguards concerns, public authority misdescription, finance-boundary overclaims, procurement overclaims, certification overclaims, sponsor or provider misuse, and unresolved corrective actions. Issues shall be assigned owners, severity, deadlines, escalation, evidence, corrective action, and closeout criteria. Issues shall not be hidden because they are reputationally inconvenient.

408.3 Control Register. GCRI Canada may maintain a control register identifying key controls, control owners, purpose, risk addressed, frequency, evidence required, operating status, exceptions, testing results, deficiencies, remediation, and review dates. Controls may relate to corporate filings, tax filings, privacy, AI governance, cybersecurity, research ethics, sanctions, export controls, competition, procurement neutrality, public authority references, finance-boundary language, sponsorship acceptance, data access, publication review, and records. Control registers shall support validity-by-record.

408.4 Key Risk Indicators. GCRI Canada may define key risk indicators to monitor emerging or increasing risk. KRIs may include missed filings, unresolved compliance issues, access exceptions, unauthorized tool use, AI incidents, cyber incidents, publication corrections, public authority reference corrections, sponsor concentration, provider concentration, unresolved conflicts, overdue access reviews, overdue training, privacy incidents, public-safe publication holds, sanctions hits, export-control escalations, competition incidents, and overdue remediation. KRIs shall be used for prevention and escalation, not superficial scoring.

408.5 Key Performance Indicators. GCRI Canada may define key performance indicators for public-benefit stewardship, program delivery, publication discipline, training completion, technical asset maintenance, public-good software continuity, public-safe review completion, correction turnaround, accessibility improvements, safeguards completion, Board oversight, and compliance execution. KPIs shall not incentivize overclaim, unsafe publication, rushed review, sponsor pleasing, provider preference, public authority over-proximity, finance-boundary drift, or neglect of correctionability. KPIs shall be interpreted with risk and quality context.

408.6 Risk Appetite Statements. Risk appetite statements shall describe the level of risk GCRI Canada is prepared to accept in defined domains. GCRI Canada shall have low or no appetite for legal violations, public authority delegation by implication, public warning overclaim, emergency command overclaim, sanctions breach, export-control breach, privacy breach, protected knowledge misuse, research fabrication, cyber negligence, finance-boundary breach, procurement steering, certification overclaim, private inurement, retaliation, harassment, fraud, corruption, and failure to correct. Innovation appetite shall be controlled and mission-aligned.

408.7 Risk Tolerances. Risk tolerances may define thresholds for escalation, Board reporting, access restriction, publication hold, legal review, safeguards review, cyber review, privacy review, export-control review, sanctions review, competition review, sponsor concentration, provider concentration, donor concentration, incident severity, KRI triggers, and overdue remediation. Tolerances shall be realistic, measurable where possible, and adjustable as GCRI Canada matures. Exceeding tolerance shall trigger review and action.

408.8 Three Lines Model Where Appropriate. GCRI Canada may adopt a three lines model or equivalent governance model where appropriate to its maturity. The first line shall own operational risk; the second line shall provide compliance, risk, data, AI, cyber, privacy, safeguards, finance-boundary, public authority-boundary, and research integrity oversight; and the third line shall provide audit, assurance, independent review, or external review where appropriate. The model may be scaled but shall preserve segregation, independence, and escalation for material risks.

408.9 First-Line Operational Ownership. First-line owners include program owners, research leads, publication owners, technical asset owners, repository custodians, Academy leads, partnership owners, finance personnel, data owners, public authority interface owners, and other persons responsible for day-to-day activities. First-line ownership requires identifying risks, applying controls, maintaining records, completing reviews, escalating issues, protecting data, correcting errors, and ensuring that outputs remain within approved scope. First-line owners shall not self-approve high-risk exceptions unless authorized by policy.

408.10 Second-Line Compliance, Risk, Data, AI, Cyber, and Safeguards Oversight. Second-line oversight may include compliance leads, risk leads, privacy leads, data governance leads, AI governance leads, cybersecurity leads, safeguards leads, public authority boundary reviewers, finance-boundary reviewers, procurement-neutrality reviewers, research integrity reviewers, publication reviewers, legal reviewers, or equivalent functions. Second-line oversight shall challenge, review, approve, monitor, and escalate within defined authority. Second-line functions shall not become rubber stamps for first-line speed or sponsor pressure.

408.11 Third-Line Audit, Assurance, or Independent Review Where Appropriate. Third-line review may include audit, review engagement, external assurance, legal review, cybersecurity assessment, privacy assessment, research integrity review, safeguards review, Board-commissioned review, funder-required review, or independent expert review. Third-line review shall be used where risk, complexity, law, funder terms, public authority terms, Board decision, or institutional maturity warrants. Findings shall be recorded, assigned, remediated, and reported to the Board or appropriate authority.

408.12 Segregation of Duties. GCRI Canada shall maintain segregation of duties proportionate to resources and risk. Segregation may require separating request, approval, payment, reconciliation, access granting, access review, publication drafting, publication approval, conflict review, benchmark administration, clean-room access, repository release, vendor selection, contract approval, and financial reporting. Where full segregation is not feasible, compensating controls, Board oversight, dual review, or retrospective review shall be used. No person should control a high-risk process end-to-end without review.

408.13 Control Testing. GCRI Canada may test controls periodically or after incidents. Control testing may include access review, payment review, publication review sampling, privacy review, AI-use review, cybersecurity testing, backup restoration testing, sanctions screening testing, export-control review testing, competition meeting review, procurement-neutrality claim review, sponsorship benefit review, conflict review, and records testing. Deficiencies shall be classified, remediated, and tracked.

408.14 Issue Remediation. Issues shall be remediated through corrective actions proportionate to severity and root cause. Remediation may include policy change, training, system change, access restriction, contract amendment, publication correction, public authority clarification, data deletion, AI tool restriction, cybersecurity remediation, conflict mitigation, sponsor benefit change, provider claim correction, refund, termination, disciplinary action, or Board review. Remediation shall include owner, deadline, evidence of completion, and closeout review.

408.15 Escalation Thresholds. GCRI Canada shall define escalation thresholds for risks, issues, incidents, exceptions, breaches, missed deadlines, public authority matters, data / AI / cyber matters, privacy matters, protected knowledge matters, finance-boundary matters, procurement matters, certification matters, sanctions matters, export-control matters, competition matters, workplace matters, and fraud matters. Escalation thresholds shall identify when matters go to officers, committees, Board Chair, full Board, counsel, external experts, insurers, public authorities, regulators, funders, or affected persons.

408.16 Board Reporting. The Board shall receive risk, issue, control, compliance, incident, insurance, audit, financial, public authority boundary, data / AI / cyber, privacy, safeguards, sanctions, export-control, competition, procurement-neutrality, finance-boundary, and strategic risk reporting as appropriate. Board reporting shall be accurate, concise, source-supported, limitation-bearing, and action-oriented. Material risks shall not be sanitized for optics. Reports shall identify decisions needed, residual risk, overdue matters, and corrective actions.

408.17 Risk, Issue, Control, KRI, KPI, and Remediation Records. GCRI Canada shall maintain risk, issue, control, KRI, KPI, and remediation records, including risk register records, issue register records, control register records, key risk indicator records, key performance indicator records, risk appetite statements, risk tolerance records, three lines model records where adopted, first-line ownership records, second-line oversight records, third-line review records, segregation of duties records, control testing records, issue remediation records, escalation threshold records, Board reporting records, corrective action evidence, closeouts, and archives.


Section 409. Third-Party Risk, Provider Risk, Vendor Risk, Sponsor Risk, Host Risk, Cloud Risk, AI Provider Risk, Data Processor Risk, and International Partner Risk

409.1 Third-Party Risk Purpose. GCRI Canada shall maintain third-party risk controls to ensure that providers, vendors, sponsors, donors, funders, hosts, partners, cloud providers, AI providers, data processors, cybersecurity providers, repository providers, international partners, public authority interfaces, community interfaces, and protected knowledge interfaces do not create unacceptable legal, financial, data, AI, cyber, privacy, research integrity, public authority, finance-boundary, procurement, certification, competition, sanctions, export-control, reputational, operational, continuity, or capture risk. Third-party relationships shall support public-benefit purpose and shall not compromise legal separateness, non-execution, provider neutrality, sponsor non-control, public-safe claims, or correctionability.

409.2 Provider Risk. Provider risk includes risk arising from technology providers, service providers, cloud providers, AI providers, cybersecurity providers, telecom providers, AI-RAN providers, O-RAN providers, DePIN providers, software providers, data providers, consultants, contractors, National Consortium Companies, Project SPVs, and other enterprise actors. Provider risk may involve provider preference, procurement implication, benchmark manipulation, public authority access purchase, sponsor-like influence, data rights, cybersecurity, vendor lock-in, public claims, conflicts, competition law, and dependency. Provider relationships shall be neutral, documented, reviewed, and correctionable.

409.3 Vendor Risk. Vendor risk includes risk from suppliers of goods or services, including legal, accounting, audit, insurance, software, cloud, security, events, publications, accessibility, translation, payment processing, collaboration tools, repositories, data rooms, Academy platforms, and facilities. Vendor risk review shall assess legal status, capability, security, privacy, data processing, financial stability, conflicts, related-party issues, sanctions, export controls, contract terms, insurance, service continuity, exit readiness, and public claims. Vendor selection shall follow procurement controls.

409.4 Sponsor Risk. Sponsor risk includes risk that sponsorship creates control, influence, reputation laundering, public authority access purchase, provider preference, procurement advantage, finance-readiness influence, certification influence, recognition implication, research distortion, public-safe publication pressure, or sponsor overclaim. Sponsor risk shall be controlled through acceptance tests, benefit schedules, sponsor non-control, public acknowledgment review, influence caps, conflict review, public authority boundary review, provider-neutrality review, and correction rights. Sponsor support shall remain support-without-control.

409.5 Donor and Funder Risk. Donor and funder risk includes risk from funding concentration, restricted conditions, reporting pressure, source-of-funds concerns, tax treatment, private benefit, donor control, grantor control, public authority-linked funding, cross-border funding, reputational risk, and mission drift. Donor and funder risk shall be managed through screening, acceptance tests, restricted-fund controls, reporting controls, no-control-for-cash rules, related-party review, tax review, and Board oversight for high capture risk.

409.6 Host Risk. Host risk includes risk arising from host institutions, facilities, universities, laboratories, public authorities, public institutions, community hosts, infrastructure hosts, lab hosts, data-room hosts, controlled-room hosts, and Academy hosts. Host risk may include safety, accessibility, public authority confusion, public claims, data control, facility security, insurance, public authority delegation implication, procurement implication, provider preference, protected knowledge, community pressure, and closeout. Hosting shall not imply endorsement, operational control, public authority approval, certification, finance-readiness, or procurement approval.

409.7 Cloud Provider Risk. Cloud provider risk includes data residency, encryption, access control, logging, incident response, subprocessors, AI-enabled services, vendor lock-in, billing risk, service continuity, backup, deletion, public authority data handling, protected knowledge handling, cross-border transfer, sanctions, export controls, cyber risk, and exit readiness. Cloud providers shall be reviewed before use with sensitive data or critical systems. Cloud dependency shall not compromise GCRI Canada’s independence, correctionability, or public-good asset continuity.

409.8 AI Provider Risk. AI provider risk includes model training on GCRI Canada data, retention, logging, confidentiality, hallucinations, fabricated citations, prompt injection, output ownership, data leakage, agentic action, cross-border processing, public authority data exposure, protected knowledge exposure, cyber-sensitive exposure, infrastructure-sensitive exposure, bias, transparency, service continuity, vendor lock-in, and public-safe publication risk. AI providers shall be approved before use and restricted by data class, purpose, user role, and output type.

409.9 Data Processor Risk. Data processor risk includes risk from third parties processing personal information, public authority data, research data, health-sensitive data, participant data, Academy data, donor data, sponsor data, employee data, contractor data, protected participation records, or controlled-room records. Data processors shall be reviewed and controlled through processing instructions, confidentiality, security, subprocessors, cross-border terms, breach notification, AI-use restrictions, model-training prohibitions where required, retention, deletion, and return obligations.

409.10 Cybersecurity Provider Risk. Cybersecurity provider risk includes risk from managed security services, vulnerability scanners, penetration testers, incident response providers, logging providers, identity providers, endpoint providers, threat intelligence providers, repository security providers, and cyber consultants. Review shall address access to sensitive systems, confidentiality, data rights, export controls, vulnerability disclosure, conflicts, incident handling, subcontractors, insurance, competence, and public claims. Cybersecurity providers shall not publicly imply certification or security guarantee unless authorized and accurate.

409.11 Repository Provider Risk. Repository provider risk includes access control, repository availability, branch protection, secrets exposure, public/private visibility, dependency management, issue tracking, pull request exposure, contributor access, artifact storage, export controls, sanctions, data residency, public authority data exclusion, protected knowledge exclusion, backup, takedown, account ownership, and exit readiness. Repository providers and repository settings shall be reviewed for public-good software, controlled software, technical baselines, and sensitive materials.

409.12 International Partner Risk. International partner risk includes cross-border legal compliance, sanctions, export controls, tax, privacy, data transfer, controlled technology, public authority sensitivity, political risk, corruption risk, human rights risk, public claims, role confusion, institutional capacity, IP, confidentiality, protected knowledge, public authority boundaries, and enforceability. International partnerships shall be documented, reviewed, limited by scope, and designed to preserve GCRI Canada’s legal separateness, public-benefit purpose, non-execution, and correctionability.

409.13 Public Authority Interface Risk. Public authority interface risk includes risk that a third party uses GCRI Canada’s public authority engagement to imply endorsement, adoption, procurement approval, funding approval, regulatory approval, public finance approval, public-private partnership, sovereign obligation, public warning, emergency command, or provider preference. Public authority interface risk shall be controlled through capacity classification, reference approvals, non-endorsement language, access controls, sponsor and provider claim review, and correction.

409.14 Community and Protected Knowledge Risk. Third parties may create community and protected knowledge risk through data access, mapping, AI processing, publication, sponsor access, provider access, public authority-facing use, capital-reader use, or community engagement. GCRI Canada shall assess whether third parties can comply with community protocols, Indigenous rights, consent, non-consent, withdrawal, correction, confidentiality, public-safe mapping, protected knowledge restrictions, accessibility, grievance, and remedy. Third-party access may be denied where safeguards cannot be assured.

409.15 Due Diligence. Third-party due diligence shall be proportionate to risk and may include legal status, ownership, beneficial ownership where appropriate, sanctions screening, export-control review, reputation, competence, financial stability, insurance, conflicts, public authority relationships, privacy, cybersecurity, AI terms, data rights, IP, human rights, anti-corruption, competition risk, public claims history, references, and exit readiness. Due diligence shall occur before engagement and may be refreshed upon renewal, material change, incident, or risk escalation.

409.16 Contract Controls. Third-party contracts shall include controls appropriate to risk, including scope, authority, confidentiality, data rights, privacy, cybersecurity, AI-use restrictions, model-training prohibitions where required, public authority terms, protected knowledge terms, IP, publication rights, public claims restrictions, non-endorsement, no-public-authority-delegation, no-procurement-approval, no-finance-readiness, no-certification, sanctions, export controls, audit or assurance rights where appropriate, incident notification, termination, access revocation, data return or deletion, and closeout.

409.17 Monitoring. Third parties may be monitored during the relationship for performance, compliance, public claims, data handling, AI use, cyber posture, incident history, conflicts, ownership changes, sanctions changes, export-control issues, public authority references, sponsor or provider overclaims, service continuity, subcontractors, and unresolved issues. Monitoring shall be proportionate to risk and may include periodic reviews, access reviews, reporting, attestations, audits where appropriate, issue tracking, and renewal review. Material changes shall be escalated.

409.18 Exit Readiness. GCRI Canada shall maintain exit readiness for material third parties, including cloud providers, AI providers, repositories, data processors, cybersecurity providers, Academy platforms, payment processors, sponsors, hosts, and key vendors. Exit readiness may include data export, data deletion, replacement provider options, access revocation, contract termination, continuity plan, public claims correction, asset return, IP handling, credential rotation, repository transfer, backup, and closeout. Dependency shall not prevent correction, withdrawal, security response, or institutional continuity.

409.19 Third-Party Risk Records. GCRI Canada shall maintain third-party risk records, including third-party risk purpose records, provider risk records, vendor risk records, sponsor risk records, donor and funder risk records, host risk records, cloud provider risk records, AI provider risk records, data processor risk records, cybersecurity provider risk records, repository provider risk records, international partner risk records, public authority interface risk records, community and protected knowledge risk records, due diligence records, contract control records, monitoring records, exit readiness records, incidents, corrections, restrictions, terminations, closeouts, and archives.


Section 410. Insurance

410.1 Insurance Purpose. GCRI Canada may maintain insurance to protect its corporate continuity, directors, officers, employees, contractors, volunteers, fellows, advisors, committee members where eligible, public-benefit programs, events, research activities, technical assets, data / AI / cyber activities, controlled rooms, publications, travel, property, and financial integrity against insurable risks. Insurance shall support prudent governance and institutional resilience, but shall not be treated as permission to breach law, fiduciary duties, public authority boundaries, finance boundaries, procurement neutrality, certification boundaries, confidentiality, privacy, cybersecurity, research ethics, safeguards, or this Bylaw.

410.2 Board Authority to Obtain Insurance. The Board may authorize GCRI Canada to obtain, renew, amend, replace, cancel, or decline insurance coverage, and may delegate insurance administration to officers or authorized persons. Insurance decisions shall consider GCRI Canada’s size, budget, legal duties, public authority interfaces, data sensitivity, AI use, cybersecurity exposure, research activities, events, travel, controlled rooms, publications, employment matters, contracts, funder requirements, host requirements, public-good technical assets, and risk appetite. Material uninsured risk may require Board review.

410.3 Directors’ and Officers’ Insurance. GCRI Canada may obtain directors’ and officers’ liability insurance to protect eligible directors and officers against covered claims arising from lawful service to GCRI Canada. D&O insurance shall not eliminate fiduciary duties, conflict duties, good-faith duties, public-benefit duties, mission fidelity, non-execution duties, or compliance obligations. Coverage terms, exclusions, limits, retention, reporting requirements, claims-made status, prior acts, and renewal conditions shall be reviewed and recorded.

410.4 General Liability Insurance. GCRI Canada may obtain general liability insurance for covered bodily injury, property damage, premises, events, programs, meetings, Academy activities, public sessions, labs, controlled-room activities, community participation, and other activities. General liability coverage shall be reviewed in light of venues, hosts, travel, public participation, volunteers, fellows, contractors, public authority participants, community participants, and accessibility needs. Insurance shall not replace safety planning, host agreements, accessibility planning, or risk review.

410.5 Professional Liability or Errors and Omissions Insurance. GCRI Canada may obtain professional liability or errors and omissions insurance where its research, methods, publications, technical baselines, public-safe summaries, Academy activities, consulting-like activities where lawful, technical support, software, data analysis, public authority learning, or controlled outputs create insurable professional-risk exposure. Such insurance shall not authorize regulated professional opinions, legal advice, engineering sign-offs, clinical advice, investment advice, insurance advice, accounting advice, rating opinions, procurement approval, public authority decisions, or certification by default.

410.6 Cyber Insurance. GCRI Canada may obtain cyber insurance for covered cyber incidents, privacy incidents, data breaches, ransomware, business interruption, incident response, forensic services, legal services, notification costs, public relations, restoration costs, and related risks. Cyber insurance shall be reviewed in light of public authority data, protected knowledge, personal information, health-sensitive data, repositories, AI tools, cloud environments, public-good software, dashboards, maps, controlled rooms, and payment systems. Cyber insurance shall not replace cybersecurity controls, approved tools, access management, or incident response.

410.7 Employment Practices Insurance. GCRI Canada may obtain employment practices liability insurance or equivalent coverage where appropriate for claims involving employment, contractors, volunteers, fellows, advisors, discrimination, harassment, retaliation, wrongful dismissal, workplace complaints, or related matters. Such coverage shall not reduce GCRI Canada’s duties to maintain lawful, safe, accessible, respectful, anti-retaliatory, and non-discriminatory workplace and participation environments. Employment practices risks shall also be managed through policies, training, documentation, and grievance pathways.

410.8 Property Insurance. GCRI Canada may obtain property insurance for owned, leased, borrowed, hosted, or controlled property, including equipment, computers, servers, storage devices, sensors, lab equipment, office property, event equipment, public-good technical assets, and other physical assets. Property coverage shall be coordinated with asset registers, in-kind contribution records, host agreements, custody records, maintenance responsibilities, insurance obligations, and closeout. Insurance shall not resolve ambiguous ownership or custody.

410.9 Event Insurance. GCRI Canada may obtain event insurance for conferences, workshops, Academy sessions, public authority learning sessions, community sessions, labs, hackathons, challenges, simulations, tabletop exercises, public meetings, fundraising events, sponsor events, and other gatherings. Event insurance review shall consider venue requirements, public attendance, public authority participants, community participants, accessibility, safety, travel, cancellation, weather, public health considerations, cyber or hybrid-event risks, and contractual indemnities. Event coverage shall not create public authority endorsement or emergency command.

410.10 Fiduciary Insurance. GCRI Canada may obtain fiduciary insurance where appropriate to address fiduciary responsibilities relating to benefit plans, restricted funds, endowment-like funds where any, pension-like arrangements where any, or other fiduciary exposures. Fiduciary insurance shall not reduce duties of prudence, loyalty, care, restricted-fund compliance, conflict management, no-private-inurement, donor restriction compliance, or Board oversight. Fiduciary risks shall be recorded and reviewed.

410.11 Crime, Fraud, or Fidelity Insurance. GCRI Canada may obtain crime, fraud, or fidelity insurance for covered losses involving theft, fraud, employee dishonesty, payment diversion, forgery, cyber-enabled financial fraud, social engineering, funds transfer fraud, or similar risks. Such coverage shall be reviewed alongside fraud controls, payment controls, segregation of duties, bank controls, vendor verification, reimbursement controls, corporate card controls, and financial incident response. Insurance shall not excuse weak controls or failure to investigate.

410.12 Research, Lab, Travel, or Special Program Insurance Where Appropriate. GCRI Canada may obtain research, lab, travel, fieldwork, equipment, participant, volunteer, fellow, community engagement, international activity, controlled-room, public authority learning, technical testing, or special program insurance where risk warrants. Special program insurance shall be reviewed for public authority interfaces, host requirements, data / AI / cyber exposure, physical safety, community safeguards, protected knowledge, international travel, export-control issues, and contractual obligations. Coverage gaps shall be escalated before high-risk program launch.

410.13 Insurance Review Cycle. GCRI Canada shall review insurance periodically and upon material change, including new programs, new jurisdictions, increased public authority engagement, controlled-room expansion, public-good software release, AI tool deployment, cyber exposure, employment growth, event expansion, international collaboration, major funding, new hosts, new facilities, new technical assets, incidents, claims, legal changes, or Board direction. Review shall assess limits, deductibles, retentions, exclusions, claims-made requirements, notice requirements, insured persons, additional insureds, contractual obligations, and affordability.

410.14 Insurance Claims Management. Insurance claims and potential claims shall be identified, reported, managed, and documented according to policy terms, notice requirements, legal advice, Board oversight where material, confidentiality, privilege, public authority terms, privacy, cybersecurity, employment, fraud, and incident response requirements. GCRI Canada shall preserve records, avoid prejudicing coverage, coordinate communications, and track claim status, insurer responses, coverage positions, settlements, recoveries, and lessons learned. Claims management shall not suppress required corrections or public-safe notices.

410.15 Insurance Not as Waiver of Duties. Insurance shall not waive, reduce, or excuse duties under law, the Articles, this Bylaw, Board resolutions, contracts, public authority terms, privacy obligations, cybersecurity obligations, research ethics, employment standards, safeguards, public-safe publication rules, non-execution boundaries, finance boundaries, procurement neutrality, certification boundaries, public authority boundaries, or fiduciary obligations. Insured persons remain responsible for lawful, good-faith, prudent, loyal, public-benefit, and mission-faithful conduct. Insurance proceeds shall be handled according to law, policy, accounting rules, and any restrictions.

410.16 Insurance Records. GCRI Canada shall maintain insurance records, including insurance purpose records, Board authority records, policies, binders, certificates, endorsements, renewals, cancellations, coverage summaries, directors’ and officers’ insurance records, general liability records, professional liability or errors and omissions records, cyber insurance records, employment practices insurance records, property insurance records, event insurance records, fiduciary insurance records, crime / fraud / fidelity insurance records, research / lab / travel / special program insurance records, review cycle records, claim records, potential claim notices, insurer correspondence, coverage decisions, recoveries, lessons learned, no-waiver-of-duties records, closeouts, and archives.

Section 411. Indemnification, Advancement of Expenses, Exclusions, and Liability Limits

411.1 Indemnification Purpose. GCRI Canada may indemnify eligible persons to the extent permitted by applicable law in order to protect lawful, good-faith service to GCRI Canada, preserve institutional continuity, support competent governance, attract qualified directors, officers, committee members, employees, contractors, volunteers, fellows, advisors, and representatives, and ensure that persons acting within authorized roles are not unfairly exposed to personal cost solely because they served GCRI Canada’s public-benefit purpose. Indemnification shall be interpreted as a protective governance mechanism, not as permission to breach fiduciary duties, legal duties, public-benefit duties, confidentiality obligations, data / AI / cyber obligations, research integrity obligations, public authority boundaries, finance boundaries, procurement neutrality, certification boundaries, protected knowledge safeguards, or this Bylaw.

411.2 Indemnification to Extent Permitted by Law. GCRI Canada may indemnify eligible persons only to the extent permitted by applicable law, the Articles, this Bylaw, Board-approved policy, insurance terms, and any applicable contract. No indemnification shall be provided where prohibited by law or where the person’s conduct falls within an exclusion that cannot lawfully be indemnified. If applicable law limits indemnification, advancement, liability protection, or expense reimbursement, the lawful limit shall govern. If applicable law requires court approval, member approval, Board approval, repayment undertaking, or other condition, GCRI Canada shall comply with that condition before or as part of providing indemnification or advancement.

411.3 Eligible Persons. Eligible persons may include current and former directors, officers, committee members where eligible, employees, contractors, volunteers, fellows, advisors, representatives, agents, and other persons who acted for or at the request of GCRI Canada in an authorized role, to the extent permitted by law and approved by competent authority. Eligibility shall be determined by role, authority, scope, conduct, good faith, legal permissibility, conflict status, insurance status, and records. Participation alone, public authority status, sponsor status, provider status, donor status, host status, advisory status, controlled-room access, technical contribution, or public visibility shall not automatically create indemnification rights unless expressly approved or required by law.

411.4 Directors. GCRI Canada may indemnify directors for eligible claims, proceedings, investigations, expenses, liabilities, settlements, judgments, penalties, or costs arising from lawful service as directors, subject to applicable law, good-faith requirements, fiduciary duties, Board records, insurance terms, and exclusions. Director indemnification shall protect legitimate governance service but shall not protect bad faith, fraud, willful misconduct, knowing legal violation, improper personal benefit, intentional public authority overclaim, deliberate finance-boundary breach, intentional data misuse, retaliation, harassment, corruption, or conduct that applicable law excludes from indemnification.

411.5 Officers. GCRI Canada may indemnify officers for eligible claims, proceedings, investigations, expenses, liabilities, settlements, judgments, penalties, or costs arising from lawful service as officers within authorized scope, subject to applicable law, good-faith requirements, lawful conduct requirements, delegated authority records, insurance terms, and exclusions. Officer indemnification shall not extend to unauthorized commitments, knowing misstatements, unlawful public authority representations, improper finance-readiness claims, procurement steering, certification overclaims, misuse of funds, unauthorized AI or data processing, cyber misconduct, retaliation, or acts outside authority unless lawfully approved and not excluded.

411.6 Committee Members Where Eligible. GCRI Canada may indemnify committee members, Board committee members, advisory committee members, council participants, working-party members, expert-panel members, peer reviewers, model reviewers, safeguards reviewers, or other review participants where eligible and approved, but only for authorized service within recorded mandate and lawful scope. Advisory, committee, or council participation shall not expand indemnification beyond the person’s role. Indemnification shall not cover conduct undertaken as a provider, sponsor, donor, public authority, capital actor, employer representative, vendor, or personal actor outside GCRI Canada’s authorized process.

411.7 Employees, Contractors, Volunteers, Fellows, Advisors, and Representatives Where Eligible and Approved. GCRI Canada may indemnify employees, contractors, volunteers, fellows, advisors, seconded personnel, representatives, or agents where permitted by law, approved by competent authority, and appropriate to the person’s authorized role. Such indemnification may be provided by contract, policy, Board resolution, insurance, or case-specific approval. Eligibility shall require that the person acted within scope, in good faith, for GCRI Canada’s public-benefit purpose, and without excluded misconduct. Indemnification shall not convert the person into an officer, director, fiduciary, public authority, certifier, finance-readiness authority, procurement authority, or professional advisor unless separately and lawfully recorded.

411.8 Conditions of Indemnification. Indemnification may be conditioned on timely notice, cooperation, preservation of records, non-admission without approval where appropriate, compliance with insurer requirements, conflict disclosure, truthful statements, return of materials, confidentiality, mitigation of loss, and compliance with Board or officer instructions. GCRI Canada may condition indemnification on separate counsel review where conflicts exist. Failure to comply with reasonable conditions may limit, suspend, or deny indemnification to the extent permitted by law.

411.9 Good Faith Requirement. Indemnification shall require that the eligible person acted in good faith, or otherwise satisfied the standard required by applicable law. Good faith includes honest conduct, absence of intentional deception, reasonable belief in authority, respect for public-benefit purpose, and willingness to correct errors. Conduct undertaken to mislead public authorities, influence procurement, purchase recognition, evade sanctions, bypass export controls, misuse data, conceal AI errors, suppress corrections, retaliate, harass, defraud, or obtain improper private benefit shall not satisfy the good-faith requirement.

411.10 Lawful Conduct Requirement. Indemnification shall require that the eligible person’s conduct was lawful or otherwise indemnifiable under applicable law. Where a matter involves alleged legal violation, GCRI Canada may defer final indemnification determination until facts, proceedings, settlement terms, legal advice, or final disposition clarify eligibility. GCRI Canada may provide advancement where lawful and conditioned on repayment where required, but advancement shall not predetermine final indemnification. Conduct known by the person to be unlawful, or deliberately indifferent to clear legal restrictions, may be excluded.

411.11 Best-Interest Requirement Where Applicable. Where applicable law requires that a person acted in the best interests of GCRI Canada, or with a reasonable belief that the conduct was in the best interests of GCRI Canada, indemnification shall be conditioned on that standard. The best interests of GCRI Canada include public-benefit mission, nonprofit character, legal separateness, non-execution, public authority boundaries, finance boundaries, provider neutrality, research integrity, data / AI / cyber integrity, protected knowledge safeguards, public-safe claims discipline, validity-by-record, and correctionability. Private interest, sponsor pressure, provider pressure, donor pressure, public authority pressure, personal gain, or reputational convenience shall not override GCRI Canada’s best interests.

411.12 Exclusions for Bad Faith, Fraud, Willful Misconduct, Knowing Legal Violation, Improper Personal Benefit, or Other Excluded Conduct Under Law. GCRI Canada shall not indemnify conduct excluded by applicable law. Excluded conduct may include bad faith, fraud, willful misconduct, knowing legal violation, intentional breach of duty, improper personal benefit, corruption, bribery, kickbacks, theft, embezzlement, retaliation, harassment, discrimination, intentional data misuse, intentional AI misuse, cyber misconduct, protected knowledge misuse, intentional public authority overclaim, intentional finance overclaim, intentional certification overclaim, intentional procurement steering, or other conduct for which indemnification is prohibited. The Board may adopt additional exclusions consistent with law.

411.13 Advancement of Expenses Where Lawful. GCRI Canada may advance reasonable expenses to eligible persons where lawful, appropriate, approved, and subject to required conditions. Advancement may cover legal fees, defense costs, investigation costs, expert costs, or other reasonable expenses incurred in connection with eligible service. Advancement shall be reviewed for legal permissibility, insurance coverage, conflict, scope, proportionality, available funds, restricted-fund limitations, and repayment undertaking where required. Advancement shall not be treated as final determination of entitlement to indemnification.

411.14 Repayment Undertaking Where Required. Where applicable law, Board policy, insurance terms, or approval conditions require repayment undertaking, an eligible person receiving advancement shall provide an undertaking to repay amounts advanced if it is ultimately determined that the person is not entitled to indemnification. The undertaking may be unsecured unless law or Board policy requires otherwise. Failure to provide required undertaking may justify denial or delay of advancement. Repayment obligations shall be recorded and enforced where required.

411.15 Board Approval and Conflict Controls. Indemnification and advancement decisions shall be approved by the Board, a Board-authorized committee, disinterested directors, officers where delegated, or another lawful decision authority, subject to conflict controls. A person seeking indemnification or advancement shall not participate in approval of their own request except to provide information. Where Board conflicts are material, GCRI Canada may obtain independent legal advice, committee review, member approval where required, court approval where required, or another lawful process. Records shall identify conflicts, recusals, approvals, conditions, and rationale.

411.16 Liability Limitation to Extent Permitted by Law. To the extent permitted by applicable law, the Articles, this Bylaw, and lawful agreements, GCRI Canada may limit liability of eligible persons for lawful, good-faith service within authorized scope. Any limitation shall be interpreted narrowly and shall not limit liability where prohibited by law or where conduct involves bad faith, fraud, willful misconduct, knowing legal violation, improper personal benefit, breach of fiduciary duty that cannot be limited, retaliation, harassment, corruption, intentional data misuse, protected knowledge misuse, or other excluded conduct. Liability limits shall not impair correction, remedy, public-safe clarification, or compliance obligations.

411.17 No Indemnification as Permission to Breach Duties. No indemnification, advancement, insurance, liability limitation, Board approval, officer approval, contract clause, public authority relationship, sponsor relationship, provider relationship, donor relationship, or program urgency shall be interpreted as permission to breach duties. Eligible persons remain responsible for good faith, care, loyalty, prudence, lawful conduct, confidentiality, conflicts, data / AI / cyber duties, research integrity, public authority boundaries, finance boundaries, procurement neutrality, professional boundaries, protected knowledge, public-safe publication, and correction. Indemnification is protection for lawful service, not immunity for misconduct.

411.18 Indemnification and Advancement Records. GCRI Canada shall maintain indemnification and advancement records, including indemnification purpose records, legal permissibility records, eligible person determinations, director indemnification records, officer indemnification records, committee member indemnification records, employee / contractor / volunteer / fellow / advisor / representative indemnification records, condition records, good-faith determinations, lawful conduct determinations, best-interest determinations, exclusion reviews, advancement records, repayment undertakings, Board approvals, conflict controls, liability limitation records, no-permission-to-breach records, insurance coordination records, counsel review records, payment records, denial records, repayment records, closeouts, and archives.


Section 412. Incident Taxonomy, Severity Levels, Intake, Triage, Interim Relief, Stop / Hold Measures, Investigation Standards, and Decision Authorities

412.1 Incident Taxonomy Purpose. GCRI Canada shall maintain an incident taxonomy to classify, intake, triage, investigate, contain, remediate, correct, record, and learn from incidents affecting legal compliance, corporate governance, nonprofit integrity, research integrity, evidence and methods integrity, data protection, privacy, AI governance, cybersecurity, public authority boundaries, finance boundaries, procurement neutrality, certification boundaries, recognition boundaries, public warning boundaries, sponsor and provider non-control, community safeguards, protected knowledge, public-safe publication, workplace conduct, and institutional continuity. The taxonomy shall ensure that incidents are handled by severity and substance rather than by reputational convenience.

412.2 Legal Incident. A legal incident includes an actual, suspected, threatened, or potential breach of law, regulation, court order, corporate obligation, tax obligation, privacy obligation, employment obligation, contract obligation, sanctions requirement, export-control requirement, competition law, public authority term, research ethics requirement, insurance condition, or professional boundary requirement. Legal incidents shall be escalated to appropriate officers, counsel, the Board, insurer, public authority, regulator, funder, or other body where required or appropriate.

412.3 Governance Incident. A governance incident includes unauthorized decision-making, invalid meeting process, quorum failure, notice failure, conflict failure, recusal failure, unauthorized delegation, unauthorized signing, Board record error, officer authority overreach, member rights issue where applicable, committee authority overreach, advisory body overclaim, legal separateness breach, shared liability risk, or Nexus role-separation failure. Governance incidents shall be corrected through ratification where lawful, reversal, record correction, re-approval, conflict remediation, authority clarification, or Board review.

412.4 Research Integrity Incident. A research integrity incident includes fabrication, falsification, plagiarism, fabricated citation, source manipulation, evidence suppression, method manipulation, data manipulation, AI-assisted fabrication, undisclosed conflict, sponsor-controlled conclusion, provider-controlled conclusion, peer review breach, authorship misconduct, protected knowledge misuse, community research breach, unsafe publication, or failure to correct research error. Research integrity incidents shall be reviewed in a fair, source-supported, conflict-controlled, and correctionable manner.

412.5 Evidence or Methods Incident. An evidence or methods incident includes materially inaccurate evidence, stale evidence, missing source lineage, unsupported claim, invalid method, unreproducible result, flawed benchmark, dashboard error, map error, model error, ontology error, semantic mapping error, false precision, limitation omission, versioning error, public-safe classification error, or technical baseline error. Such incidents shall trigger evidence review, methods review, output correction, dependency review, public-safe clarification where needed, and record correction.

412.6 Data or Privacy Incident. A data or privacy incident includes unauthorized collection, use, disclosure, access, retention, deletion failure, cross-border transfer, personal information exposure, health-sensitive data exposure, public authority data misuse, protected participation exposure, re-identification risk, data processor failure, unapproved storage, shadow IT use, personal drive use, public repository exposure, or breach notification event. Data and privacy incidents shall be contained, investigated, notified where required, corrected, and recorded.

412.7 AI Incident. An AI incident includes hallucination, fabricated citation, unsafe output, data leakage, unauthorized AI upload, unauthorized model training, embedding misuse, retrieval failure, prompt injection, unauthorized agent action, model drift, bias, discriminatory output, public overclaim, public authority misdescription, finance overclaim, certification overclaim, procurement overclaim, recognition overclaim, maturity overclaim, or direct publication of unreviewed AI output. AI incidents shall be classified, contained, corrected, and reviewed for tool restriction, model suspension, training, or vendor escalation.

412.8 Cybersecurity Incident. A cybersecurity incident includes unauthorized access, credential compromise, phishing, malware, ransomware, repository exposure, secrets exposure, cloud misconfiguration, vulnerability exploitation, system compromise, data exfiltration, dashboard compromise, map compromise, payment diversion, denial of service, supplier breach, AI tool security issue, or public-good software vulnerability. Cybersecurity incidents shall trigger containment, evidence preservation, access restriction, forensic review where appropriate, notification where required, remediation, post-incident review, and security record updates.

412.9 Public Authority Boundary Incident. A public authority boundary incident includes misdescription of public authority capacity, unauthorized public authority reference, public authority logo misuse, quote misuse, attendance overclaim, data contribution overclaim, implied endorsement, implied adoption, public warning implication, emergency command implication, regulatory approval implication, procurement approval implication, funding approval implication, public finance approval implication, sovereign obligation implication, public-private partnership implication, or public authority delegation implication. Such incidents require prompt correction and public authority reference review.

412.10 Finance, Insurance, Investment, Procurement, Certification, Recognition, or Public Warning Boundary Incident. A boundary incident includes any statement, output, report, dashboard, map, evidence pack, proof pack, Academy record, benchmark, challenge result, sponsor material, provider material, public authority material, or Nexus-compatible claim that implies investment advice, securities solicitation, insurance approval, underwriting, lending approval, rating, finance-readiness, public finance approval, procurement approval, vendor selection, certification, accreditation, compliance approval, recognition, maturity, public warning, emergency command, or official determination. Boundary incidents shall be contained, corrected, and reviewed for systemic controls.

412.11 Sponsor, Donor, Provider, Host, or Capture Incident. A capture incident includes attempted or actual sponsor control, donor control, funder control, provider influence, host pressure, public authority pressure, restricted-fund pressure, benefit inflation, improper private benefit, research agenda distortion, publication suppression, benchmark manipulation, challenge manipulation, public authority access purchase, procurement advantage, finance-readiness influence, certification influence, recognition purchase, provider preference, or pressure to avoid correction. Capture incidents shall be escalated and may require recusal, restriction, disclosure, termination, return of funds, or Board review.

412.12 Community Safeguards or Protected Knowledge Incident. A community safeguards or protected knowledge incident includes breach of consent, non-consent, withdrawal, attribution, community protocol, Indigenous governance protocol, FPIC where applicable, protected knowledge access, cultural site exposure, environmental knowledge exposure, unsafe mapping, AI misuse of protected knowledge, retaliation, community harm, inaccessible participation, grievance mishandling, or do-no-harm failure. Such incidents shall receive heightened safeguards review, containment, correction, remedy, and closeout.

412.13 Public-Safe Publication or Claims Incident. A public-safe publication or claims incident includes unsupported public claim, public authority overclaim, finance overclaim, certification overclaim, procurement overclaim, public warning overclaim, emergency command implication, confidential disclosure, protected knowledge disclosure, data disclosure, AI-generated error, fabricated citation, missing limitation, stale status, misleading dashboard, misleading map, sponsor overclaim, provider overclaim, or unsafe social media, speech, deck, report, article, dataset, software release, or public dashboard. Publication may be held, corrected, withdrawn, superseded, or clarified.

412.14 Workplace, Harassment, Retaliation, or Conduct Incident. A workplace, harassment, retaliation, or conduct incident includes harassment, discrimination, violence, threats, intimidation, retaliation, protected participation violation, whistleblower retaliation, exclusion, abuse of authority, conflict abuse, confidentiality breach, misconduct by staff, directors, contractors, fellows, advisors, volunteers, participants, sponsors, providers, hosts, public authority participants, or other persons interacting with GCRI Canada. Such incidents shall be handled with confidentiality, fairness, non-retaliation, interim measures, investigation, remedy, and records.

412.15 Severity Levels. GCRI Canada shall classify incidents by severity using a Board-approved or officer-approved severity scale. Severity may consider legal exposure, public safety, public authority confusion, data sensitivity, AI risk, cyber risk, protected knowledge, community harm, financial impact, research integrity, publication status, public visibility, sponsor or provider misuse, recurrence, intent, number of affected persons, regulatory reporting, insurance notification, and correction urgency. Severity levels may include low, moderate, elevated, high, severe, critical, or another approved scale. Severity determines escalation, authority, timelines, containment, and Board reporting.

412.16 Intake and Case ID. Incidents shall be intaken through approved channels and assigned a case identifier where appropriate. Intake shall capture reporter, date, affected materials, affected systems, affected persons, category, severity indicators, immediate risk, evidence, source records, public status, public authority involvement, data / AI / cyber involvement, protected knowledge involvement, sponsor or provider involvement, requested action, and confidentiality needs. Intake shall not be dismissed solely because the report is inconvenient, anonymous where allowed, incomplete, critical, or reputationally sensitive.

412.17 Triage. Triage shall determine incident class, severity, immediate containment needs, interim relief, decision authority, investigation pathway, legal review, counsel involvement, Board escalation, insurer notice, public authority notice, privacy notification, cyber response, safeguards review, publication hold, access restriction, and communication limits. Triage shall occur promptly and proportionately. Triage decisions shall be recorded and may be updated as facts change.

412.18 Interim Relief. GCRI Canada may provide interim relief or protective measures where necessary to protect persons, data, public authority clarity, protected knowledge, systems, records, research integrity, public-safe status, or institutional integrity. Interim relief may include non-contact instructions, access restrictions, publication holds, data holds, AI-use holds, repository freezes, role changes, temporary suspension, confidentiality reminders, public-safe clarification, support for affected persons, or referral. Interim relief shall not presume final findings.

412.19 Stop, Hold, Quarantine, Freeze, Access Restriction, Publication Suspension, or Technical Isolation. GCRI Canada may stop work, hold a release, quarantine data, freeze repository activity, restrict access, suspend publication, disable dashboards, restrict maps, isolate systems, suspend AI tools, suspend controlled-room access, pause payments, hold public authority references, pause sponsor benefits, pause provider participation, or take other containment action where incident risk warrants. Such measures shall preserve evidence, minimize harm, prevent escalation, and allow investigation. Measures shall be recorded and reviewed for continuation or release.

412.20 Investigation Standards. Investigations shall be fair, proportionate, timely, evidence-based, conflict-controlled, confidentiality-aware, trauma-informed where appropriate, privacy-aware, safeguards-aware, and legally reviewed where needed. Investigations shall preserve relevant records, interview relevant persons where appropriate, review source materials, assess intent and impact, identify root causes, consider aggravating and mitigating factors, protect against retaliation, and produce findings or closeout records. Conflicted persons shall not control investigations involving their own conduct.

412.21 Decision Authorities. Decision authorities may include officers, the Board, Board committees, committee chairs, program owners, compliance leads, legal counsel, data / AI / cyber leads, safeguards leads, research integrity reviewers, publication approvers, repository custodians, controlled-room custodians, or external reviewers, according to incident severity and subject matter. High-severity incidents involving legal breach, public authority delegation, public warning, emergency command, sanctions, export controls, privacy breach, cyber breach, protected knowledge harm, serious misconduct, retaliation, fraud, or capture shall be escalated to senior authority or the Board where appropriate.

412.22 Incident Records. GCRI Canada shall maintain incident records, including taxonomy records, legal incident records, governance incident records, research integrity incident records, evidence or methods incident records, data or privacy incident records, AI incident records, cybersecurity incident records, public authority boundary incident records, finance / insurance / investment / procurement / certification / recognition / public warning boundary incident records, sponsor / donor / provider / host / capture incident records, community safeguards or protected knowledge incident records, public-safe publication or claims incident records, workplace / harassment / retaliation / conduct incident records, severity classifications, intake records, case IDs, triage records, interim relief records, stop / hold / quarantine / freeze / access restriction / publication suspension / technical isolation records, investigation records, decision authority records, corrective action records, closeouts, and archives.


Section 413. Enforcement, Remedies, Sanctions, Aggravating and Mitigating Factors, Due Process, Appeals, Reinstatement, and Probation

413.1 Enforcement Purpose. GCRI Canada shall maintain enforcement, remedy, sanction, appeal, reinstatement, and probation processes to ensure that violations of law, the Articles, this Bylaw, Board-approved policies, program rules, confidentiality obligations, data / AI / cyber requirements, research integrity standards, public authority boundaries, finance boundaries, procurement neutrality, certification boundaries, protected knowledge safeguards, public-safe publication rules, workplace conduct rules, or participation conditions are addressed fairly, proportionately, consistently, and correctionably. Enforcement shall protect public-benefit purpose, institutional integrity, affected persons, public trust, and Nexus role separation.

413.2 Covered Persons. Covered persons may include directors, officers, members where any, employees, contractors, consultants, volunteers, fellows, advisors, committee members, council participants, working-party members, reviewers, trainers, developers, maintainers, technical contributors, public authority participants, sponsors, donors, funders, providers, vendors, hosts, partners, Academy participants, challenge participants, benchmarking participants, controlled-room participants, data-room participants, subscribers, and other persons acting for, with, through, or in reference to GCRI Canada. Coverage may be defined by role, agreement, access, participation, or conduct.

413.3 Enforcement Intake. Enforcement matters may be initiated by incident report, grievance, whistleblowing report, audit finding, compliance review, public authority objection, sponsor or provider claim review, publication review, data / AI / cyber incident, safeguards concern, Board review, officer review, legal notice, regulator notice, funder notice, or observed violation. Intake shall identify alleged conduct, person or entity involved, affected materials, affected persons, evidence, severity, urgency, confidentiality, interim measures, and decision authority. Intake shall not presume guilt.

413.4 Notice Where Appropriate. Where appropriate, lawful, safe, and consistent with investigation integrity, GCRI Canada shall provide notice to the person or entity subject to enforcement. Notice may identify the concern, applicable rule, process, response opportunity, interim measures, confidentiality expectations, non-retaliation obligations, and potential consequences. Notice may be delayed, limited, or omitted where required to protect evidence, safety, confidentiality, whistleblowers, protected knowledge, legal privilege, cyber response, public authority obligations, or investigation integrity.

413.5 Response Opportunity Where Appropriate. Where appropriate, GCRI Canada shall provide a reasonable opportunity to respond to allegations before final adverse action, unless immediate action is required or response is impractical, unsafe, legally constrained, or inconsistent with the applicable relationship. The response opportunity may be written, oral, interview-based, or through counsel where appropriate. Response rights shall be proportionate to role, severity, contractual rights, legal requirements, and risk. Emergency containment may occur before response.

413.6 Investigation. Enforcement investigations shall follow the investigation standards in this Bylaw and shall be conducted by persons with appropriate authority, independence, competence, and absence of material conflict. Investigations may include document review, system log review, publication review, interview, data review, AI output review, repository review, financial review, public authority reference review, safeguards review, legal review, or external expert review. Investigations shall distinguish fact, inference, intent, impact, legal conclusion, and corrective recommendation.

413.7 Findings. Findings may determine that a violation occurred, did not occur, could not be substantiated, requires further review, requires correction without misconduct finding, requires policy clarification, requires training, or requires referral. Findings shall be supported by records and shall identify applicable rules, evidence, severity, aggravating factors, mitigating factors, remedies, sanctions, corrective actions, appeal rights where any, and closeout conditions. Findings may be confidential, controlled, or public-safe depending on subject matter and risk.

413.8 Remedies. Remedies may include correction, public-safe clarification, controlled notice, apology, withdrawal, retraction, data deletion, map revision, dashboard correction, repository correction, publication correction, access restoration, access restriction, training, process change, safeguards improvement, reimbursement, refund, return of funds, termination of benefit, contract amendment, support to affected persons, or other action designed to repair harm or reduce risk. Remedies may be imposed with or without punitive sanctions.

413.9 Corrective Action. Corrective action may include policy revision, training, supervision, conflict mitigation, recusal, role restriction, access restriction, publication hold, tool restriction, AI restriction, cyber remediation, vendor remediation, sponsor benefit modification, provider claim correction, public authority reference correction, safeguards review, data reclassification, record correction, contract amendment, or Board review. Corrective action shall address root cause where feasible and shall be assigned owner, deadline, evidence of completion, and closeout.

413.10 Access Restriction. GCRI Canada may restrict access to systems, repositories, rooms, data, publications, dashboards, maps, controlled materials, public authority materials, protected knowledge, finance-sensitive evidence, Academy programs, challenge programs, benchmarking programs, committees, councils, events, or communications where risk warrants. Access restriction may be interim or final, partial or complete, time-limited or indefinite, and may be conditioned on training, corrective action, reinstatement review, or monitoring.

413.11 Recusal or Role Restriction. GCRI Canada may require recusal, role restriction, removal from decision lane, separation from review, exclusion from public authority interface, exclusion from finance-sensitive materials, exclusion from procurement-sensitive materials, exclusion from publication approval, exclusion from controlled-room access, or limitation of public statement authority where conflict, misconduct, risk, or appearance of capture warrants. Role restrictions shall be recorded and communicated to relevant administrators.

413.12 Suspension. GCRI Canada may suspend participation, access, role, benefits, committee seat, council role, fellowship, Academy access, repository access, controlled-room access, sponsor benefits, provider participation, program participation, publication involvement, or contracting activity pending investigation or as final sanction. Suspension shall be proportionate to severity and may be imposed immediately where needed to protect persons, records, systems, public authority clarity, protected knowledge, or public-safe status.

413.13 Termination. GCRI Canada may terminate employment, contract, volunteer role, fellowship, advisory role, committee participation, council participation, program participation, subscription, sponsorship, provider participation, host relationship, controlled-room access, repository access, or other relationship where permitted by law and agreement and warranted by conduct, risk, breach, non-remediation, conflict, misconduct, or incompatibility with public-benefit purpose. Termination may require offboarding, access revocation, return of materials, data deletion, public claims correction, final payment, refund review, and records.

413.14 Removal From Committee, Council, Fellowship, Program, Room, Repository, or Participation Surface. GCRI Canada may remove a person or entity from a committee, council, fellowship, program, working party, review panel, competence cell, Academy session, controlled room, data room, clean room, repository, challenge, benchmark, lab, public authority learning activity, or other participation surface where conduct, conflict, misuse, overclaim, confidentiality breach, data misuse, AI misuse, cyber misconduct, harassment, retaliation, capture risk, or safeguards breach warrants removal. Removal shall be recorded and may be accompanied by public-safe correction where needed.

413.15 Contractual Remedies. Where violations arise under contract, GCRI Canada may use contractual remedies, including cure notice, suspension, termination, withholding, refund, indemnity claim, insurance claim, audit right, data return, data deletion, IP assignment enforcement, confidentiality enforcement, public claims correction, access revocation, injunctive relief where appropriate, dispute process, or other remedy. Contractual remedies shall be coordinated with legal review where material.

413.16 Public or Controlled Correction. GCRI Canada may issue public or controlled correction where enforcement matters involve public misstatement, public authority overclaim, finance overclaim, procurement overclaim, certification overclaim, recognition overclaim, sponsor or provider misuse, data misuse, AI error, cyber exposure, protected knowledge disclosure, public-safe publication error, or use of GCRI Canada name. Correction may include revised language, takedown, withdrawal, retraction, public-safe clarification, controlled notice, participant notice, public authority notice, sponsor or provider notice, dashboard note, map note, or archive note.

413.17 Referral to Legal Counsel, Regulator, Public Authority, Law Enforcement, Funder, Partner, or Other Body Where Required or Appropriate. GCRI Canada may refer matters to legal counsel, regulator, public authority, law enforcement, insurer, funder, donor, sponsor, host, partner, university, laboratory, professional body, research ethics body, public authority data provider, or other body where required by law, contract, public authority terms, insurance, research ethics, safeguarding obligations, or severity. Referral shall be reviewed for confidentiality, privacy, protected knowledge, retaliation risk, legal privilege, public-safe status, and affected persons.

413.18 Aggravating Factors. Aggravating factors may include intent, bad faith, concealment, repeat violation, retaliation, harassment, fraud, corruption, abuse of authority, vulnerable person harm, protected knowledge misuse, public authority overclaim, public warning overclaim, emergency command overclaim, finance overclaim, procurement overclaim, certification overclaim, data leakage, AI misuse, cyber misconduct, sponsor or provider pressure, conflict concealment, personal benefit, refusal to correct, record destruction, and harm to public trust. Aggravating factors may increase remedy or sanction severity.

413.19 Mitigating Factors. Mitigating factors may include good-faith mistake, prompt self-reporting, cooperation, lack of prior violations, limited impact, immediate correction, evidence preservation, remedial action, training need, unclear policy, system failure, reliance on inaccurate internal records, absence of personal benefit, and willingness to repair harm. Mitigating factors may reduce severity but shall not prevent correction, public-safe clarification, access restriction, or remediation where required.

413.20 Due Process. GCRI Canada shall apply due process appropriate to the role, relationship, severity, law, contract, and risk. Due process may include notice, response opportunity, impartial review, conflict control, evidence review, reasoned decision, appeal where available, confidentiality, non-retaliation, and recordkeeping. Due process shall not prevent immediate interim measures where needed to protect safety, data, systems, public authority clarity, protected knowledge, public-safe status, or legal obligations.

413.21 Appeals. Appeals may be available where provided by law, contract, policy, Board decision, or program rules. Appeals may be based on procedural defect, new evidence, material error, disproportionate sanction, conflict, misrepresentation, legal requirement, or public-safe necessity. Appeal authority shall be independent where reasonably possible and shall not include materially conflicted persons. Appeals may affirm, modify, reverse, remand, or impose conditions. Appeal decisions shall be recorded.

413.22 Reinstatement. Reinstatement may occur where suspension, termination, removal, access restriction, or role restriction is no longer necessary and where risk has been resolved, mitigated, corrected, or accepted within approved limits. Reinstatement may require training, renewed confidentiality, revised access, probation, monitoring, apology, correction, repayment, conflict mitigation, Board approval, or legal review. Reinstatement shall not erase records of prior incidents unless law or policy requires sealing or correction.

413.23 Probation and Monitoring. GCRI Canada may impose probation or monitoring where continued participation is permitted but risk remains. Conditions may include limited access, supervision, training, periodic review, no-public-statement restriction, no-public-authority-interface restriction, no-controlled-room access, no-repository release authority, no-finance-sensitive materials, no-sponsor or provider-facing role, conflict mitigation, or conduct undertakings. Probation violations may trigger suspension or termination.

413.24 Enforcement Records. GCRI Canada shall maintain enforcement records, including enforcement purpose records, covered person records, intake records, notices, response opportunities, investigation records, findings, remedies, corrective action records, access restrictions, recusal or role restrictions, suspensions, terminations, removals, contractual remedies, public or controlled corrections, referrals, aggravating factor records, mitigating factor records, due process records, appeal records, reinstatement records, probation and monitoring records, confidentiality records, non-retaliation records, closeouts, and archives.


Section 414. Misrepresentation, Name Misuse, Public Authority Overclaim, Finance Overclaim, Certification Overclaim, Data Misuse, AI Misuse, Cyber Misconduct, Sponsor Capture, Provider Capture, and Conflict Violations

414.1 Misrepresentation. No person shall misrepresent GCRI Canada, its legal status, nonprofit status, charitable status, public-benefit purpose, authority, outputs, programs, records, Board decisions, officer authority, public authority relationships, finance-boundary posture, procurement posture, certification posture, recognition posture, Nexus-compatible role, or public-good technical assets. Misrepresentation includes false, misleading, incomplete, outdated, exaggerated, unauthorized, or contextually deceptive statements in public materials, private communications, donor reports, sponsor materials, provider materials, public authority communications, capital-reader materials, media, websites, decks, dashboards, maps, datasets, repositories, or social media.

414.2 Name Misuse. No person shall use the GCRI Canada name, abbreviation, marks, institutional identity, officer names, Board names, program names, Academy names, lab names, challenge names, technical asset names, Nexus-compatible terms, public authority references, or institutional language without authorization or outside approved terms. Name misuse includes implying endorsement, approval, certification, procurement preference, finance-readiness, public authority access, public authority adoption, public warning, emergency command, recognition, maturity, official partnership, or authority to bind GCRI Canada.

414.3 Mark, Logo, Badge, Report, Dataset, Software, Technical Baseline, and Public-Good Asset Misuse. No person shall misuse GCRI Canada marks, logos, badges, reports, datasets, software, schemas, APIs, SDKs, dashboards, maps, model cards, system cards, technical baselines, ontology files, public-good assets, Academy materials, certificates of attendance where any, records, or public-safe summaries. Misuse includes unauthorized copying, alteration, marketing, resale, false attribution, misleading excerpt, unauthorized badge use, false compliance claim, false procurement claim, false certification claim, false finance-readiness claim, public authority overclaim, or removal of limitations and correction notices.

414.4 Public Authority Overclaim. No person shall overclaim public authority involvement with GCRI Canada. Public authority overclaim includes implying endorsement, adoption, public authority delegation, official mandate, regulatory approval, public warning, emergency command, procurement approval, funding approval, public finance approval, public-private partnership, sovereign obligation, public policy adoption, public infrastructure adoption, official safety determination, official health determination, official security determination, or official resilience determination where no competent record supports the claim. Public authority overclaims require correction.

414.5 Finance, Insurance, Investment, Lending, Underwriting, Rating, Public Finance, Capital-Readiness, or Bankability Overclaim. No person shall claim or imply that GCRI Canada provides investment advice, securities advice, solicitation, brokerage, finder services, capital placement, underwriting, lending approval, guarantee, insurance approval, insurance placement, rating, public finance approval, bankability, investability, finance-readiness, insurance-readiness, capital-readiness, creditworthiness, public guarantee, MDB approval, DFI approval, public credit approval, or transaction recommendation. Technical evidence inputs, proof pack literacy, and Nexus Rails references shall remain non-reliance and non-executing.

414.6 Certification, Accreditation, Conformance, Procurement, Recognition, Maturity, Grid, Docket, or Nexus-Compatible Overclaim. No person shall claim or imply certification, accreditation, compliance approval, conformance approval, procurement approval, vendor selection, recognition, standing, maturity, Grid status, Docket validity, Nexus-compatible official status, public legitimacy, or provider preference by reason of GCRI Canada participation, technical baseline use, Academy attendance, challenge participation, benchmark inclusion, lab participation, public authority attendance, sponsor support, provider contribution, or public-safe publication. Any such claim must be supported by competent authority outside GCRI Canada where applicable and approved language.

414.7 Data Misuse. Data misuse includes unauthorized collection, use, access, disclosure, transfer, publication, retention, deletion failure, re-identification, combination, scraping, extraction, AI upload, model training, embedding, indexing, public repository placement, sponsor disclosure, provider disclosure, capital-reader disclosure, public authority-facing misuse, or use beyond permitted purpose. Data misuse may involve personal information, public authority data, health-sensitive data, research data, cyber-sensitive data, infrastructure-sensitive data, community data, Indigenous data, protected knowledge, finance-sensitive evidence, or controlled-room materials. Data misuse shall trigger containment and correction.

414.8 AI Misuse. AI misuse includes use of unapproved AI tools, uploading restricted materials to AI systems, unauthorized model training, unauthorized embeddings, unauthorized retrieval indexes, hallucinated citations, fabricated sources, public release of unreviewed AI output, use of AI as decision authority, unauthorized agent actions, AI-generated public authority overclaims, AI-generated finance overclaims, AI-generated certification overclaims, data leakage, prompt injection mishandling, bias, discriminatory outputs, and failure to disclose AI use where required. AI misuse shall be treated as a compliance, data, and public-safe issue.

414.9 Cyber Misconduct. Cyber misconduct includes unauthorized access, credential sharing, bypassing MFA, secrets exposure, malicious code, repository compromise, unauthorized scanning, unauthorized penetration testing, vulnerability disclosure breach, malware, data exfiltration, system tampering, shadow IT, unapproved storage, unapproved tool use, cloud misconfiguration caused by misconduct, public authority data exposure, protected knowledge exposure, or failure to report a cybersecurity incident. Cyber misconduct may require access revocation, investigation, notification, legal review, and remediation.

414.10 Repository Misconduct. Repository misconduct includes unauthorized commits, unauthorized releases, branch protection bypass, secrets upload, controlled data upload, public authority data upload, protected knowledge upload, license violation, dependency manipulation, malicious contribution, AI-generated code without required review, false authorship, unauthorized deletion, false issue reporting, release note overclaim, public-good asset misuse, or repository access abuse. Repository misconduct shall be reviewed by repository custodians, technical stewards, legal or security reviewers where appropriate, and corrected.

414.11 Protected Knowledge Misuse. Protected knowledge misuse includes unauthorized collection, disclosure, publication, mapping, AI processing, sponsor disclosure, provider disclosure, public authority-facing use, capital-reader use, attribution, translation, extraction, commercialization, public-safe misclassification, or failure to respect consent, non-consent, withdrawal, community protocol, Indigenous governance protocol, FPIC where applicable, cultural site restrictions, environmental knowledge safeguards, or custodial restrictions. Protected knowledge misuse shall receive heightened safeguards review and may require remedy.

414.12 Sponsor Capture. Sponsor capture includes any attempt by a sponsor to control or materially influence governance, research agenda, evidence selection, methods, publication timing, public authority access, public claims, dashboards, maps, Academy content, benchmarks, challenge outcomes, technical baselines, software, recognition language, finance-readiness language, procurement language, correction decisions, staffing, or Board decisions. Sponsor capture may occur through funding pressure, benefit schedules, public visibility, renewal threats, in-kind dependency, or relationship leverage. Sponsor capture is prohibited.

414.13 Provider Capture. Provider capture includes any attempt by a provider or vendor to use GCRI Canada to obtain provider preference, procurement advantage, benchmark advantage, certification implication, finance-readiness implication, public authority access, technical baseline control, software control, research conclusion control, public-safe output control, challenge advantage, Academy influence, or public claims leverage. Provider capture is prohibited and may require exclusion, claim correction, contract termination, access restriction, or public-safe clarification.

414.14 Donor, Funder, Host, Investor, Insurer, Lender, Contractor, or Public Authority Capture. Capture may also arise from donors, funders, hosts, investors, insurers, lenders, contractors, public authorities, universities, laboratories, National Consortium Companies, Project SPVs, or other actors. Capture includes pressure to alter findings, suppress negative results, expand public authority language, create finance-readiness implication, influence procurement, influence certification, alter public-safe language, bypass safeguards, expose protected knowledge, or avoid correction. GCRI Canada shall resist capture regardless of source.

414.15 Conflict Violation. A conflict violation includes failure to disclose a conflict, failure to update a conflict, participation after required recusal, misuse of role for personal or institutional benefit, undisclosed sponsor or provider relationship, related-party concealment, influence on procurement, influence on research conclusions, influence on public authority access, influence on finance-sensitive outputs, or use of confidential information for private advantage. Conflict violations shall be investigated, corrected, and recorded.

414.16 Retaliation, Harassment, or Protected Participation Violation. Retaliation, harassment, discrimination, intimidation, exclusion, threats, reputation harm, contract retaliation, funding retaliation, career retaliation, academic retaliation, community retaliation, sponsor pressure, provider pressure, public authority pressure, or adverse treatment for good-faith reporting, dissent, non-consent, withdrawal, correction request, grievance, stop-the-line use, protected knowledge concern, or safeguards concern is prohibited. Protected participation violations shall be treated as serious misconduct.

414.17 Investigation and Remedy. Violations under this Section shall be investigated according to incident and enforcement procedures. Remedies may include correction, public-safe clarification, controlled notice, access restriction, role restriction, recusal, suspension, termination, contract remedy, data deletion, AI restriction, repository takedown, sponsor benefit restriction, provider claim correction, public authority clarification, safeguards remedy, repayment, referral, or Board review. Remedies shall address root cause and downstream misuse where feasible.

414.18 Public-Safe Correction. Where a violation creates public misunderstanding, public authority confusion, finance overclaim, certification overclaim, procurement overclaim, public warning implication, emergency command implication, provider preference, sponsor control implication, data disclosure, AI error, cyber exposure, protected knowledge exposure, or unsafe publication, GCRI Canada shall issue public-safe correction or controlled correction as appropriate. Correction shall be clear, timely, proportionate, and traceable to affected materials.

414.19 Violation Records. GCRI Canada shall maintain violation records, including misrepresentation records, name misuse records, mark / logo / badge / report / dataset / software / technical baseline / public-good asset misuse records, public authority overclaim records, finance / insurance / investment / lending / underwriting / rating / public finance / capital-readiness / bankability overclaim records, certification / accreditation / conformance / procurement / recognition / maturity / Grid / Docket / Nexus-compatible overclaim records, data misuse records, AI misuse records, cyber misconduct records, repository misconduct records, protected knowledge misuse records, sponsor capture records, provider capture records, donor / funder / host / investor / insurer / lender / contractor / public authority capture records, conflict violation records, retaliation / harassment / protected participation violation records, investigation and remedy records, public-safe correction records, closeouts, and archives.


Section 415. Emergency Integrity and Security Governance

415.1 Emergency Integrity Purpose. GCRI Canada shall maintain emergency integrity governance to permit timely, disciplined, lawful, and record-supported action during urgent integrity, compliance, data, AI, cyber, public authority, safeguards, publication, finance-boundary, procurement-boundary, certification-boundary, or institutional continuity events. Emergency integrity governance shall preserve public-benefit purpose, legal separateness, non-execution, public authority boundaries, public-safe claims discipline, validity-by-record, correctionability, and Nexus role separation under pressure. Emergency procedures shall not be used to bypass Board oversight, suppress dissent, conceal misconduct, or normalize exceptional authority.

415.2 Emergency Security Purpose. GCRI Canada shall maintain emergency security governance to protect systems, records, data, public authority materials, protected knowledge, research assets, public-good technical assets, repositories, dashboards, maps, AI systems, financial accounts, communications, controlled rooms, and institutional continuity during security-sensitive events. Emergency security actions may include access restriction, credential rotation, repository freeze, system isolation, dashboard shutdown, map restriction, AI tool suspension, publication hold, payment hold, vendor escalation, forensic preservation, and public-safe communication.

415.3 Activation Triggers. Emergency integrity or security governance may be activated when delay could materially worsen legal risk, public safety risk, public authority confusion, cyber risk, privacy harm, AI harm, protected knowledge harm, community harm, research integrity harm, financial harm, public-safe publication harm, sponsor or provider capture, finance overclaim, procurement overclaim, certification overclaim, recognition overclaim, public warning overclaim, emergency command overclaim, sanctions risk, export-control risk, regulatory deadline risk, or institutional continuity risk. Activation shall be recorded and proportionate.

415.4 Data Breach Trigger. A data breach, suspected data breach, personal information exposure, health-sensitive data exposure, public authority data exposure, protected participation record exposure, protected knowledge exposure, unauthorized transfer, public repository exposure, or unapproved AI upload may trigger emergency governance. Actions may include containment, access restriction, notification assessment, legal review, privacy review, public authority notice where required, affected person notice where required, vendor escalation, public-safe correction, and post-incident review.

415.5 Cybersecurity Trigger. A cybersecurity incident, suspected compromise, credential breach, ransomware, malware, repository compromise, secrets exposure, cloud misconfiguration, dashboard compromise, map compromise, payment diversion, AI system security issue, vulnerability exploitation, or critical supplier breach may trigger emergency governance. Actions may include technical isolation, credential rotation, system shutdown, repository freeze, forensic preservation, insurer notice, cyber counsel review, public authority notice where required, and remediation.

415.6 AI Incident Trigger. An AI incident, including hallucination in external content, fabricated citation, unsafe output, unauthorized agent action, unauthorized AI data processing, data leakage, model drift, bias, prompt injection, retrieval failure, public authority misdescription, finance overclaim, certification overclaim, procurement overclaim, or publication of unreviewed AI output, may trigger emergency governance. Actions may include output withdrawal, AI tool suspension, model restriction, publication correction, access restriction, human review, vendor notice, and AI incident review.

415.7 Public Authority Misdescription Trigger. A public authority misdescription, unauthorized logo use, title misuse, quote misuse, attendance overclaim, public authority data overclaim, implied endorsement, implied adoption, public warning implication, emergency command implication, regulatory approval implication, procurement approval implication, funding approval implication, public finance approval implication, sovereign obligation implication, or public-private partnership implication may trigger emergency governance. Actions may include public-safe clarification, controlled notice, takedown, public authority notice, sponsor or provider correction, and Board escalation.

415.8 Public-Safe Publication Error Trigger. A public-safe publication error, including unsupported claim, missing limitation, sensitive data disclosure, protected knowledge exposure, geospatial exposure, public authority overclaim, finance overclaim, certification overclaim, procurement overclaim, public warning implication, emergency command implication, AI fabrication, dashboard error, map error, dataset error, or software release error, may trigger emergency governance. Actions may include publication hold, correction, withdrawal, retraction, archive note, downstream review, and public-safe communications.

415.9 Sponsor or Provider Capture Trigger. Sponsor or provider capture, attempted influence, benefit misuse, public claims misuse, public authority access purchase, benchmark manipulation, challenge manipulation, procurement advantage, technical baseline influence, publication suppression, research distortion, correction resistance, or public-safe language pressure may trigger emergency governance. Actions may include benefit suspension, access restriction, claim correction, contract review, Board review, refusal of support, return of funds where appropriate, or termination.

415.10 Finance, Procurement, Certification, Recognition, or Public Warning Overclaim Trigger. Any claim or output implying finance-readiness, bankability, investment suitability, insurance approval, lending approval, underwriting approval, rating, public finance approval, procurement approval, vendor selection, certification, accreditation, compliance approval, recognition, standing, maturity, public warning, emergency command, public authority decision, or official adoption by GCRI Canada may trigger emergency governance. Actions may include immediate hold, correction, withdrawal, non-reliance clarification, sponsor or provider notice, public authority notice where appropriate, and legal review.

415.11 Community Harm or Protected Knowledge Trigger. Risk of community harm, Indigenous rights harm, protected knowledge exposure, cultural site exposure, environmental knowledge exposure, unsafe mapping, non-consent violation, withdrawal failure, retaliation, inaccessible participation, sponsor or provider misuse, public authority misuse, AI inference harm, or do-no-harm failure may trigger emergency governance. Actions may include stop-work, publication hold, data restriction, map restriction, community notice where appropriate, safeguards review, remedy, withdrawal, or Board escalation.

415.12 Legal Deadline or Regulatory Risk Trigger. A legal deadline, filing deadline, regulatory notice, tax deadline, privacy notification deadline, insurance notice deadline, court deadline, funder deadline, public authority deadline, sanctions issue, export-control issue, employment deadline, or contractual deadline may trigger emergency governance where ordinary processes cannot act quickly enough. Emergency action shall be limited to preserving rights, meeting obligations, preventing harm, and creating records, and shall be ratified or reviewed as required.

415.13 Emergency Governance Team. An emergency governance team may include the Chair, officers, legal counsel, compliance lead, data / AI / cyber lead, privacy lead, safeguards lead, research integrity lead, publication approver, finance lead, repository custodian, controlled-room custodian, program owner, communications lead, or other persons necessary for the event. The team shall be limited to persons with need to know and appropriate competence. Conflicted persons shall be excluded or limited where possible. The team shall record activation, authority, actions, decisions, and closeout.

415.14 Emergency Authority Limits. Emergency authority shall be limited to actions necessary to contain risk, preserve records, protect persons, protect data, maintain legal compliance, prevent public misunderstanding, meet deadlines, secure systems, and enable review. Emergency authority shall not authorize mission drift, new regulated services, public authority delegation, public warning, emergency command, finance-readiness determination, procurement approval, certification, recognition, public-private partnership, improper spending, unauthorized contracts beyond emergency need, or suppression of required correction.

415.15 No Emergency Exercise of Prohibited Functions. No emergency shall permit GCRI Canada to exercise prohibited functions. GCRI Canada shall not issue public warnings, emergency commands, evacuation instructions, public health orders, public safety commands, public authority decisions, regulatory approvals, procurement approvals, funding approvals, public finance approvals, investment advice, insurance approvals, ratings, certifications, recognition, maturity determinations, or provider selections by invoking emergency integrity or security governance. Emergency communications shall direct persons to competent authorities where appropriate.

415.16 Time Limits and Ratification. Emergency actions shall be time-limited where feasible and shall be reviewed, ratified, modified, or terminated by the Board, Board committee, officer, counsel, or other competent authority as soon as practicable. Ratification shall identify actions taken, authority relied upon, reasons, affected materials, legal or policy basis, conflicts, costs, communications, risks, and follow-up. Actions not ratified where ratification is required shall be corrected or reversed where possible.

415.17 Communications Discipline. Emergency communications shall be accurate, public-safe, limitation-bearing, confidential where required, legally reviewed where appropriate, and aligned with public authority boundaries. Communications shall not overstate certainty, assign blame prematurely, disclose protected knowledge, expose security details, imply public warning authority, imply emergency command, imply public authority adoption, imply finance-readiness, imply procurement approval, imply certification, or compromise investigations. Spokesperson authority and approval rules shall apply unless emergency authority provides a temporary limited alternative.

415.18 Post-Emergency Review. After emergency governance activation, GCRI Canada shall conduct post-emergency review proportionate to severity. Review shall assess trigger, timeline, decisions, authority, communications, records, containment, legal compliance, data / AI / cyber response, public authority handling, safeguards, affected persons, costs, insurance, corrective actions, lessons learned, policy updates, training needs, and Board reporting. Post-emergency review shall support institutional learning and correctionability.

415.19 Emergency Integrity and Security Records. GCRI Canada shall maintain emergency integrity and security records, including emergency integrity purpose records, emergency security purpose records, activation trigger records, data breach trigger records, cybersecurity trigger records, AI incident trigger records, public authority misdescription trigger records, public-safe publication error trigger records, sponsor or provider capture trigger records, finance / procurement / certification / recognition / public warning overclaim trigger records, community harm or protected knowledge trigger records, legal deadline or regulatory risk trigger records, emergency governance team records, emergency authority limit records, no-emergency-exercise-of-prohibited-functions records, time limit and ratification records, communications records, post-emergency reviews, corrective actions, closeouts, and archives.


Section 416. Disputes, Appeals, Cross-Entity Routing, Finality, Reopening, Abuse-of-Process, Forum-Shopping Controls, and Record Synchronization

416.1 Dispute Purpose. GCRI Canada shall maintain dispute, appeal, routing, finality, reopening, abuse-of-process, forum-shopping, and record synchronization procedures to address internal governance disputes, membership and participation disputes, committee and council procedural disputes, research and technical disputes, data / AI / cyber disputes, public authority boundary disputes, finance and certification boundary disputes, safeguards disputes, sponsor and provider disputes, and cross-entity Nexus interface disputes. Dispute procedures shall support fairness, validity-by-record, role separation, legal compliance, correctionability, public trust, and institutional continuity.

416.2 Internal Governance Disputes. Internal governance disputes may include disputes concerning Board authority, officer authority, member rights where applicable, notice, quorum, voting, recusal, conflict, minutes, resolutions, delegation, committee authority, advisory body limits, signing authority, corporate filings, Bylaw interpretation, or legal separateness. Such disputes shall be routed to the Board, Chair, committee, counsel, or other competent authority according to severity and conflict. Governance validity shall be resolved by lawful records, not by informal status or institutional pressure.

416.3 Membership and Participation Disputes. Membership and participation disputes may involve statutory members where any, non-voting members, subscribers, supporters, fellows, advisors, committee participants, council participants, Academy participants, contributors, providers, sponsors, hosts, public authority participants, controlled-room participants, or other participants. Disputes may concern admission, suspension, termination, access, participation rights, public statements, confidentiality, fees, benefits, conflicts, or records. Participation disputes shall not be used to create governance rights where none exist.

416.4 Committee and Council Procedural Disputes. Committee and council procedural disputes may concern mandate, quorum, voting semantics, advisory votes, consensus indications, dissent capture, minority reports, conflicts, recusals, confidentiality, public statements, output adoption, procedural validity, or advisory authority limits. Such disputes shall be resolved according to the applicable charter, this Bylaw, Board authority, and records. Advisory bodies shall not convert procedural disputes into Board authority, public authority authority, certification authority, finance-readiness authority, or procurement authority.

416.5 Research, Evidence, Methods, and Technical Disputes. Research, evidence, methods, and technical disputes may concern data quality, source validity, method validity, reproducibility, benchmarks, dashboards, maps, models, simulations, ontology, schemas, software, technical baselines, AI outputs, peer review, authorship, attribution, publication language, correction, supersession, withdrawal, or retraction. Such disputes shall be routed to research integrity, technical review, peer review, model review, publication review, safeguards review, or Board review as appropriate. Technical dispute resolution shall remain evidence-based and correctionable.

416.6 Data, AI, Cyber, Privacy, and Controlled-Room Disputes. Data, AI, cyber, privacy, and controlled-room disputes may concern access, classification, lawful basis, permitted use, AI-use restrictions, publication restrictions, transfer restrictions, retention, deletion, breach response, model outputs, repository access, controlled-room rules, no-download restrictions, data processor terms, cloud processing, public authority data, protected knowledge, or cybersecurity controls. Such disputes shall be routed to data, privacy, AI governance, cybersecurity, legal, safeguards, or Board authorities as appropriate. Access may be held while dispute is pending.

416.7 Public Authority Boundary Disputes. Public authority boundary disputes may concern official capacity, observer status, regulator-listening status, public finance reader status, emergency-management status, public infrastructure operator status, public authority data contribution, public authority reference, logo use, quote use, adoption claim, endorsement claim, delegation claim, public warning implication, emergency command implication, procurement implication, funding implication, public finance implication, sovereign obligation implication, or public-private partnership implication. Such disputes shall be resolved conservatively, using records and approved public language.

416.8 Finance, Certification, Procurement, Recognition, and Provider-Preference Boundary Disputes. Boundary disputes may concern finance-readiness, insurance-readiness, investment advice, public finance approval, underwriting, lending, rating, procurement approval, vendor selection, certification, accreditation, conformance, compliance approval, recognition, maturity, Grid status, Docket status, Nexus-compatible status, provider preference, sponsor influence, or capital-reader use. Such disputes shall be routed to finance-boundary, procurement-neutrality, certification-boundary, legal, public claims, or Board review. GCRI Canada shall default to non-reliance and non-execution language.

416.9 Safeguards, Community, Indigenous, Protected Knowledge, and Participation Disputes. Safeguards disputes may concern community participation, accessibility, consent, non-consent, withdrawal, attribution, correction, Indigenous rights, Indigenous data, Indigenous knowledge, local knowledge, territorial knowledge, cultural sites, environmental knowledge, protected knowledge, vulnerable communities, remote communities, public-safe mapping, grievance, remedy, non-retaliation, or do-no-harm controls. Such disputes shall be routed to safeguards review, community protocol review, Indigenous governance protocol review where applicable, legal review, or Board review, with heightened protection against retaliation and extraction.

416.10 Sponsor, Donor, Provider, Host, Partner, and Third-Party Disputes. Third-party disputes may concern contracts, benefits, acknowledgment, sponsorship terms, donor restrictions, grant terms, host obligations, provider claims, vendor performance, data rights, IP, confidentiality, public statements, public authority references, procurement claims, finance claims, certification claims, controlled-room access, payments, refunds, termination, or closeout. Such disputes shall be resolved according to contracts, this Bylaw, applicable law, public-benefit purpose, sponsor non-control, provider neutrality, and correctionability.

416.11 Cross-Entity Disputes With GCRI US, The Global Risks Forum (GRF), The Global Risks Alliance (GRA), Nexus Standards, Nexus Network, Consortiums, National Companies, Project SPVs, Providers, or Other Nexus Interfaces. Cross-entity disputes may involve GCRI US, The Global Risks Forum (GRF), The Global Risks Alliance (GRA), Nexus Standards, Nexus Network, Global Nexus Consortium, Regional Nexus Consortiums, National Nexus Consortiums, National Working Groups, Nexus Competence Cells, National Consortium Companies, Project SPVs, qualified providers, hosts, sponsors, public authorities, or other Nexus interfaces. Such disputes shall preserve legal separateness, role separation, no merger, no shared treasury, no shared liability, non-execution, public authority boundaries, finance boundaries, certification boundaries, procurement neutrality, and correctionability. Routing shall identify which entity has authority over which record, output, role, or correction.

416.12 Appeals. Appeals may be available where provided by law, contract, policy, program rules, enforcement decision, Board decision, or this Bylaw. Appeals may address procedural defect, conflict, material error, new evidence, disproportionate remedy, legal requirement, public-safe necessity, safeguards concern, or jurisdictional routing error. Appeal authority shall be independent where practicable and shall not include materially conflicted decision-makers. Appeal outcomes may affirm, modify, reverse, remand, condition, reopen, or close the matter.

416.13 Finality. Final decisions shall be final when made by the competent authority after applicable process, appeal, review, or time period, subject to reopening rules, legal requirements, Board authority, court order, public authority requirement, or correctionability obligations. Finality supports institutional continuity and prevents endless relitigation, but finality shall not prevent correction of material error, public authority misdescription, protected knowledge harm, legal breach, data breach, AI error, cyber issue, or public-safe necessity.

416.14 Reopening for New Evidence, Procedural Defect, Conflict, Material Error, Misrepresentation, Legal Requirement, or Public-Safe Necessity. A matter may be reopened where material new evidence emerges, a procedural defect affected outcome, a conflict was undisclosed, a material error is identified, misrepresentation affected the decision, legal requirement demands reopening, public authority correction is required, protected knowledge risk emerges, data / AI / cyber risk emerges, or public-safe necessity requires correction. Reopening shall be authorized by competent authority and recorded. Reopening shall not be used for harassment, delay, sponsor pressure, provider pressure, or forum shopping.

416.15 Abuse-of-Process Controls. GCRI Canada may control abuse of process, including repetitive claims without new basis, knowingly false complaints, harassment through process, retaliation through process, strategic delay, evidence destruction, bad-faith appeals, sponsor or provider pressure through complaints, public authority pressure outside proper channels, or misuse of confidential processes. Abuse-of-process findings shall be made carefully so as not to chill good-faith reporting, dissent, grievance, non-consent, correction requests, whistleblowing, or safeguards escalation.

416.16 Forum-Shopping Controls. GCRI Canada shall control forum shopping within its governance and across Nexus interfaces. A person shall not repeatedly route the same dispute to different committees, councils, officers, programs, entities, public authorities, sponsors, providers, or public forums to avoid an adverse decision, pressure decision-makers, obtain inconsistent outcomes, or create public confusion. Forum-shopping controls shall preserve proper authority, legal separateness, record synchronization, and finality while allowing legitimate appeal and reopening.

416.17 Cross-Entity Routing. Where a matter belongs partly or wholly to another entity, including GCRI US, The Global Risks Forum (GRF), The Global Risks Alliance (GRA), Nexus Standards, Nexus Network, a Consortium, National Company, Project SPV, provider, host, public authority, university, laboratory, funder, or partner, GCRI Canada may route or coordinate the matter with appropriate authority. Cross-entity routing shall respect confidentiality, data rights, legal separateness, public authority boundaries, protected knowledge, privilege, and role separation. Routing shall not create shared liability, shared treasury, merger, or authority transfer.

416.18 Record Synchronization and Correction. Where disputes, appeals, corrections, withdrawals, supersessions, public authority clarifications, data corrections, AI corrections, cyber incident records, safeguards corrections, or cross-entity routing affect multiple records or entities, GCRI Canada shall synchronize records where lawful and appropriate. Record synchronization may include updating internal registers, public materials, controlled materials, Nexus interface records, public authority records, donor reports, sponsor reports, provider references, dashboards, maps, repositories, datasets, Academy materials, and archives. Synchronization shall preserve version history and correction traceability.

416.19 Dispute and Appeal Records. GCRI Canada shall maintain dispute and appeal records, including dispute purpose records, internal governance dispute records, membership and participation dispute records, committee and council procedural dispute records, research / evidence / methods / technical dispute records, data / AI / cyber / privacy / controlled-room dispute records, public authority boundary dispute records, finance / certification / procurement / recognition / provider-preference boundary dispute records, safeguards / community / Indigenous / protected knowledge / participation dispute records, sponsor / donor / provider / host / partner / third-party dispute records, cross-entity dispute records, appeal records, finality records, reopening records, abuse-of-process records, forum-shopping control records, cross-entity routing records, record synchronization and correction records, closeouts, and archives.


417.1 Compliance Record Requirement. GCRI Canada shall maintain compliance records sufficient to evidence lawful operation, corporate compliance, nonprofit compliance, tax compliance, privacy compliance, AI governance compliance, cybersecurity compliance, research ethics compliance, employment and contractor compliance, sanctions screening, export controls, controlled technology review, competition and antitrust discipline, procurement neutrality, professional-boundary controls, risk management, insurance, indemnification, incident response, investigations, enforcement, remedies, appeals, emergency integrity, dispute routing, and corrective actions. Compliance records shall support validity-by-record, Board oversight, auditability, correctionability, public trust, legal separateness, Nexus role separation, and institutional memory.

417.2 Legal Opinion Records. GCRI Canada shall maintain records of legal opinions, legal memoranda, legal advice, legal reviews, privileged communications where applicable, public authority legal reviews, tax legal reviews, privacy legal reviews, sanctions legal reviews, export-control legal reviews, employment legal reviews, corporate legal reviews, contract legal reviews, public-safe publication legal reviews, and other legal determinations. Legal opinion records shall be access-controlled and protected by privilege where applicable. Summaries may be used for operational purposes without waiving privilege where legally appropriate.

417.3 Counsel Review Records. Counsel review records shall identify the matter reviewed, counsel engaged, review scope, assumptions, documents reviewed, advice category, decision supported, conditions, limitations, privilege status, follow-up requirements, and responsible owner. Counsel review may be required for public authority delegation issues, sanctions hits, export-control uncertainty, privacy breach notification, employment disputes, indemnification, major contracts, public-private partnership language, professional-boundary issues, public finance references, certification overclaims, procurement overclaims, and high-risk corrections.

417.4 Screening Records. Screening records shall document sanctions screening, restricted-party screening, jurisdiction screening, transaction screening, payment screening, beneficial ownership review where appropriate, due diligence, public authority and state-linked entity screening where appropriate, controlled-room access screening, contributor screening, donor screening, sponsor screening, provider screening, vendor screening, contractor screening, consultant screening, partner screening, host screening, and international partner screening. Screening records shall include date, source, result, false positive resolution, escalation, denial, restriction, approval, renewal, and closeout.

417.5 Sanctions Records. Sanctions records shall include sanctions policies, screening procedures, screening results, hits, false positive analysis, restricted-party determinations, jurisdiction reviews, payment holds, transaction denials, access restrictions, legal reviews, reports where required, Board escalations, training records, and corrective actions. Sanctions records shall be retained and protected. GCRI Canada shall not disclose sanctions-sensitive records beyond authorized need, legal requirement, or appropriate reporting.

417.6 Export-Control Records. Export-control records shall include controlled technology reviews, software export reviews, data export reviews, AI model and weight export reviews, cryptography reviews, cyber tool reviews, telecom / AI-RAN / O-RAN / sensor / robotics / drone / autonomous system / satellite / geospatial / Earth observation / quantum-adjacent / semiconductor / advanced manufacturing / dual-use reviews, public release reviews, repository access reviews, controlled-room access reviews, foreign person access reviews where applicable, license or permit records, exemption analysis, legal advice, denials, restrictions, geo-fencing, redactions, re-scoping, training, and incidents.

417.7 Competition and Antitrust Records. Competition and antitrust records shall include market-conduct rules, do-not-discuss lists, meeting discipline records, council and working group discipline records, benchmarking rules, index and comparative output reviews, market baseline library controls, clean-team records, clean-room records, aggregation and de-identification records, independent administration records, market-sensitive information controls, stop-meeting records, competition incidents, legal reviews, participant notices, training, corrections, and closeouts.

417.8 Professional Boundary Records. Professional boundary records shall document no-legal-opinion, no-engineering-opinion, no-clinical-opinion, no-investment-opinion, no-insurance-opinion, no-accounting-or-tax-opinion, no-rating-opinion, no-public-health-order, no-emergency-management-order, no-public-authority-legal-interpretation, disclaimer and limitation language, professional-boundary escalations, authorized qualified professional engagements where any, professional review, corrections, withdrawals, and public-safe clarifications.

417.9 Corporate, Tax, Privacy, AI, Cyber, Research Ethics, Employment, and Contract Compliance Records. GCRI Canada shall maintain corporate compliance records, tax and nonprofit compliance records, privacy compliance records, AI governance compliance records, cybersecurity compliance records, research ethics compliance records, employment and contractor compliance records, volunteer and fellow records, advisor records, workplace compliance records, contract compliance records, grant compliance records, donation records, sponsorship records, restricted-fund records, procurement records, vendor records, public authority records, safeguards records, and public-safe publication records according to classification, retention, access, and correction requirements.

417.10 Training Records. Training records shall document role-based training, director training, officer training, staff training, contractor training, fellow training, advisor training, committee and council training, developer and maintainer training, public authority participant training, provider / sponsor / host / donor / partner boundary training, data / AI / cyber training, research integrity training, public-safe publication training, community safeguards training, sanctions training, export-control training, competition training, privacy training, cybersecurity training, AI governance training, harassment and anti-retaliation training, attendance, learning outcomes, renewal, revocation, and credential non-inflation language.

417.11 Incident Records. Incident records shall document incident intake, taxonomy, severity, case ID, triage, interim relief, stop / hold / quarantine / freeze / access restriction / publication suspension / technical isolation, investigation, decision authority, notifications, legal reviews, insurer notices, public authority notices, affected person notices where required, containment, remediation, correction, post-incident review, lessons learned, and closeout. Incident records shall include legal, governance, research integrity, evidence or methods, data or privacy, AI, cybersecurity, public authority boundary, finance / procurement / certification / recognition / public warning boundary, capture, safeguards, publication, and workplace incidents.

417.12 Investigation Records. Investigation records shall include allegations, issues, scope, investigator, conflicts, authority, evidence, interviews, system logs, documents reviewed, source materials, public authority records, data records, AI outputs, cyber records, research records, financial records, sponsor or provider materials, findings, credibility assessments where appropriate, legal reviews, confidentiality controls, interim measures, conclusions, recommendations, and closeout. Investigation records shall be protected against unauthorized disclosure and retaliation.

417.13 Enforcement Records. Enforcement records shall include enforcement intake, notices, response opportunities, investigations, findings, remedies, sanctions, access restrictions, role restrictions, recusals, suspensions, terminations, removals, contractual remedies, public or controlled corrections, referrals, aggravating factors, mitigating factors, due process records, appeal rights, appeal decisions, reinstatement, probation, monitoring, and closeout. Enforcement records shall be retained according to law, policy, contract, and institutional need.

417.14 Remedy and Sanction Records. Remedy and sanction records shall document corrective actions, public-safe clarifications, controlled notices, apologies, withdrawals, retractions, data deletion, AI restrictions, cyber remediation, access revocation, role restrictions, training, policy changes, contract amendments, sponsor benefit restrictions, provider claim corrections, public authority clarifications, repayment, refund, termination, referral, probation, monitoring, and closeout. Remedy records shall identify responsible owner, deadline, evidence of completion, and residual risk.

417.15 Corrective Action Records. Corrective action records shall document root cause, corrective action plan, owner, due date, priority, affected policy, affected system, affected record, affected publication, affected public authority reference, affected data, affected AI system, affected repository, affected sponsor or provider claim, affected community or protected knowledge, completion evidence, verification, effectiveness review, escalation, delay, extension, and closeout. Corrective actions shall not be closed merely because a statement was issued; underlying controls shall be addressed where feasible.

417.16 Appeal Records. Appeal records shall document appeal eligibility, appeal grounds, appellant, decision appealed, record on appeal, response, appeal authority, conflicts, additional evidence, hearing or written process where any, decision, reasons, remedy, finality, reopening possibility, and closeout. Appeal records shall preserve fairness and finality while protecting confidentiality, privacy, legal privilege, protected knowledge, public authority terms, and non-retaliation.

417.17 Reinstatement and Probation Records. Reinstatement and probation records shall document eligibility, conditions, risk review, training requirements, access limits, role limits, monitoring requirements, supervisor or owner, review dates, compliance evidence, violations, extensions, successful completion, failure, termination, or final reinstatement. Reinstatement shall be recorded separately from expungement; prior incident records may remain retained where lawful and necessary for institutional memory, legal compliance, and risk management.

417.18 Retention, Access, Confidentiality, Sealing, and Secure Disposal of Compliance Records. Compliance records shall be retained according to applicable law, corporate requirements, tax requirements, employment requirements, privacy requirements, research ethics requirements, public authority terms, funder terms, contract terms, insurance requirements, litigation holds, audit needs, correctionability, institutional memory, and Board policy. Access shall be limited by role, authority, need to know, confidentiality, privilege, privacy, cyber sensitivity, public authority sensitivity, protected knowledge, investigation sensitivity, and retaliation risk. Records may be sealed, restricted, anonymized, redacted, or segregated where necessary. Secure disposal shall occur only after retention requirements, legal holds, audit needs, public authority terms, protected knowledge obligations, and correctionability needs are satisfied, and shall be documented where material.

Last updated

Was this helpful?